Vulnerability Name: | CVE-2023-28486 (CCN-250349) | ||||||||||||
Assigned: | 2023-01-18 | ||||||||||||
Published: | 2023-01-18 | ||||||||||||
Updated: | 2023-04-20 | ||||||||||||
Summary: | Sudo Project Sudo could allow a remote attacker to obtain sensitive information, caused by improper escaping terminal control characters during logging operations. By sending specially crafted terminal control commands, an attacker could exploit this vulnerability to obtain restricted information information, and use this information to launch further attacks against the affected system. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:C/A:N)
| ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2023-28486 Source: XF Type: UNKNOWN sudo-cve202328486-weak-security(250349) Source: CCN Type: sudo GIT Repository Escape control characters in log messages and "sudoreplay -l" output. Source: cve@mitre.org Type: Patch cve@mitre.org Source: cve@mitre.org Type: Release Notes cve@mitre.org Source: cve@mitre.org Type: UNKNOWN cve@mitre.org | ||||||||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |