CVE-2020-36771

HIGH

CloudLinux CageFS <7.1.1-1 - Code Injection

Title source: llm
STIX 2.1

Description

CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user.

Scores

CVSS v3 7.8
EPSS 0.0007
EPSS Percentile 21.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-214 CWE-200
Status published
Products (1)
cloudlinux/cagefs < 7.1.2-2
Published Jan 22, 2024
Tracked Since Feb 18, 2026