Privilege escalation in templated-dictionary



Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2023-6395
CWE-ID CWE-254
Exploitation vector Network
Public exploit N/A
Vulnerable software
templated-dictionary
Universal components / Libraries / Programming Languages & Components

Vendor xsuchy

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Security features bypass

EUVDB-ID: #VU85880

Risk: Medium

CVSSv4.0: 4.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2023-6395

CWE-ID: CWE-254 - Security Features

Exploit availability: No

Description

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to absence of proper sandboxing during the expansion and execution of Jinja2 templates. While the Mock documentation advises treating users added to the mock group as privileged, certain build systems invoking mock on behalf of users might inadvertently permit less privileged users to define configuration tags. These tags could then be passed as parameters to mock during execution, potentially leading to the utilization of Jinja2 templates for remote privilege escalation and the execution of arbitrary code as the root user on the build server.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

templated-dictionary: 1.0-1 - 1.2-1

CPE2.3 External links

https://access.redhat.com/security/cve/CVE-2023-6395
https://bugzilla.redhat.com/show_bug.cgi?id=2252206
https://github.com/xsuchy/templated-dictionary/commit/0740bd0ca8d487301881541028977d120f8b8933
https://github.com/xsuchy/templated-dictionary/commit/bcd90f0dafa365575c4b101e6f5d98c4ef4e4b69
https://www.openwall.com/lists/oss-security/2024/01/16/1
https://www.openwall.com/lists/oss-security/2024/01/16/3


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###