CVE-2024-48911

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 14, 2024
Updated: Oct 17, 2024
CWE ID 863

Summary

CVE-2024-48911: OpenCanary's network honeypot, prior to version 0.9.4, allowed unprivileged users to modify its config file, which is stored in an unprivileged directory but executed by root. This vulnerability enabled unprivileged users to escalate permissions and directly execute commands when the root user ran the daemon. The issue has been resolved in version 0.9.4 with the implementation of a fix.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share