PT-2022-8320 · Unknown · Automationbroker/Apb

CVE-2020-10728

·

Published

2022-08-16

·

Updated

2022-08-17

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions automationbroker/apb container versions up to and including 2.0.4-1
Description A flaw in the automationbroker/apb container allows unauthorized users with access to the running container to escalate their privileges due to all users being granted sudoer permissions. This poses a significant threat to data confidentiality and integrity, as well as system availability.
Recommendations For versions up to and including 2.0.4-1, update to a version that includes a fix for this issue to prevent unauthorized privilege escalation.

Fix

Improper Privilege Management

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10728

Affected Products

Automationbroker/Apb