CVE-2020-10589

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
15/03/2020
Last modified:
17/03/2020

Description

v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/config.json is owned by a low-privileged user but contains commands that are executed as root, after v2rayL.service is restarted via Sudo.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:v2rayl_project:v2rayl:2.1.3:*:*:*:*:*:*:*