CVE-2023-6395

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 16, 2024
Updated: Feb 9, 2024
CWE ID 20

Summary

CVE-2023-6395 is a newly disclosed vulnerability affecting the Mock software. The issue allows an attacker to potentially exploit privilege escalation, granting them the ability to execute arbitrary code with root user privileges. This vulnerability arises due to the lack of proper sandboxing during the expansion and execution of Jinja2 templates in certain configuration parameters. Although the Mock documentation warns that users added to the mock group should be treated as privileged, inadvertent usage by less privileged users could lead to the definition of malicious configuration tags. These tags, if passed as parameters to Mock during execution, could trigger the utilization of Jinja2 templates for remote privilege escalation, enabling attackers to execute arbitrary code as the root user on the build server.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Fedora Operating System

Affected Vendors

  • Fedora Project