CVE-2020-36771

HIGH

CloudLinux CageFS <7.1.1-1 - Code Injection

Title source: llm
STIX 2.1

Description

CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user.

Scores

CVSS v3 7.8
EPSS 0.0047
EPSS Percentile 37.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-200 CWE-214
Status published
Products (1)
cloudlinux/cagefs < 7.1.2-2
Published Jan 22, 2024
Tracked Since Feb 18, 2026