CVE-2024-48911
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Oct 14, 2024
Updated: Oct 17, 2024
CWE ID 863
Summary
CVE-2024-48911: OpenCanary's network honeypot, prior to version 0.9.4, allowed unprivileged users to modify its config file, which is stored in an unprivileged directory but executed by root. This vulnerability enabled unprivileged users to escalate permissions and directly execute commands when the root user ran the daemon. The issue has been resolved in version 0.9.4 with the implementation of a fix.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Thinkst