configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_root_squash and insecure). In order to exploit the vulnerability, someone needs to mount an NFS share in order to add an executable file as root. In addition, the SUID bit must be added to this file.
History

Thu, 13 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Fogproject
Fogproject fogproject
CPEs cpe:2.3:a:fogproject:fogproject:*:*:*:*:*:*:*:*
Vendors & Products Fogproject
Fogproject fogproject
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 26 Aug 2024 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-250
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-13T15:53:26.010Z

Reserved: 2024-05-04T00:00:00.000Z

Link: CVE-2024-34477

cve-icon Vulnrichment

Updated: 2024-08-02T02:51:11.531Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-27T14:15:09.470

Modified: 2024-11-21T09:18:46.743

Link: CVE-2024-34477

cve-icon Redhat

No data.