Vulnerability Description
v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/config.json is owned by a low-privileged user but contains commands that are executed as root, after v2rayL.service is restarted via Sudo.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| V2Rayl Project | V2Rayl | 2.1.3 |
Related Weaknesses (CWE)
References
- https://gist.github.com/bash-c/6ac238e8b15e60c9105e8cb6b42ec43c#file-v2rayl-lpe-ExploitThird Party Advisory
- https://gist.github.com/bash-c/6ac238e8b15e60c9105e8cb6b42ec43c#file-v2rayl-lpe-ExploitThird Party Advisory
FAQ
What is CVE-2020-10589?
CVE-2020-10589 is a vulnerability with a CVSS score of 7.8 (HIGH). v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/config.json is owned by a low-privileged user but contains commands that are executed as root, after v2rayL.service is restar...
How severe is CVE-2020-10589?
CVE-2020-10589 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10589?
Check the references section above for vendor advisories and patch information. Affected products include: V2Rayl Project V2Rayl.