CVE-2019-12589

HIGH

Firejail < 0.9.60 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

In Firejail before 0.9.60, seccomp filters are writable inside the jail, leading to a lack of intended seccomp restrictions for a process that is joined to the jail after a filter has been modified by an attacker.

References (5)

Core 5

Scores

CVSS v3 8.8
EPSS 0.0008
EPSS Percentile 23.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
firejail_project/firejail < 0.9.60
Published Jun 03, 2019
Tracked Since Feb 18, 2026