Vulnerability Description
The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the root user. The risk has been accepted by the vendor and won't be fixed in the near future.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-28139?
CVE-2024-28139 is a vulnerability with a CVSS score of 8.8 (HIGH). The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the root u...
How severe is CVE-2024-28139?
CVE-2024-28139 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-28139?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.