CVE-2023-3972
published 2023-11-01CVE-2023-3972: A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and…
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.2th percentile
A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could create the /var/tmp/insights-client directory (owning the directory with read, write, and execute permissions) on the system. After the insights-client is registered by root, an attacker could then control the directory content that insights are using by putting malicious scripts into it and executing arbitrary code as root (trivially bypassing SELinux protections because insights processes are allowed to disable SELinux system-wide).
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_aus | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_power_big_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
insights-client: unsafe handling of temporary files and directories
vendor_redhat·2023-11-01·CVSS 7.8
CVE-2023-3972 [HIGH] CWE-379 insights-client: unsafe handling of temporary files and directories
insights-client: unsafe handling of temporary files and directories
A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could create the /var/tmp/insights-client directory (owning the directory with read, write, and execute permissions) on the system. After the insights-client is registered by root, an attacker could then control the directory content that insights are using by putting malicious scripts into it and executing arbitrary code as root (trivially bypassing SELinux protections because insights processes are allowed to dis
GHSA
GHSA-37f3-8h34-h4xf: A vulnerability was found in insights-client
ghsa_unreviewed·2023-11-01
CVE-2023-3972 [HIGH] CWE-379 GHSA-37f3-8h34-h4xf: A vulnerability was found in insights-client
A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could create the /var/tmp/insights-client directory (owning the directory with read, write, and execute permissions) on the system. After the insights-client is registered by root, an attacker could then control the directory content that insights are using by putting malicious scripts into it and executing arbitrary code as root (trivially bypassing SELinux protections because insights processes are allowed to disable SELinux system-wide).
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2023:6264https://access.redhat.com/errata/RHSA-2023:6282https://access.redhat.com/errata/RHSA-2023:6283https://access.redhat.com/errata/RHSA-2023:6284https://access.redhat.com/errata/RHSA-2023:6795https://access.redhat.com/errata/RHSA-2023:6796https://access.redhat.com/errata/RHSA-2023:6798https://access.redhat.com/errata/RHSA-2023:6811https://access.redhat.com/security/cve/CVE-2023-3972https://bugzilla.redhat.com/show_bug.cgi?id=2227027https://github.com/RedHatInsights/insights-core/pull/3878https://access.redhat.com/errata/RHSA-2023:6264https://access.redhat.com/errata/RHSA-2023:6282https://access.redhat.com/errata/RHSA-2023:6283https://access.redhat.com/errata/RHSA-2023:6284https://access.redhat.com/errata/RHSA-2023:6795https://access.redhat.com/errata/RHSA-2023:6796https://access.redhat.com/errata/RHSA-2023:6798https://access.redhat.com/errata/RHSA-2023:6811https://access.redhat.com/security/cve/CVE-2023-3972https://bugzilla.redhat.com/show_bug.cgi?id=2227027https://github.com/RedHatInsights/insights-core/pull/3878
2023-11-01
Published