"value":"A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-345 Insufficient Verification of Data Authenticity",
"value":"<p>There are no known workarounds for this issue.</p>"
}
],
"value":"There are no known workarounds for this issue.\n\n"
}
],
"exploit":[
{
"lang":"en",
"supportingMedia":[
{
"base64":false,
"type":"text/html",
"value":"<p>Palo Alto Networks is not aware of any malicious exploitation of this issue.</p>"
}
],
"value":"Palo Alto Networks is not aware of any malicious exploitation of this issue.\n\n"
}
],
"solution":[
{
"lang":"en",
"supportingMedia":[
{
"base64":false,
"type":"text/html",
"value":"<span style=\"background-color: rgb(255, 255, 255);\">This issue is fixed in Cortex XSOAR engine software available in Cortex XSOAR 6.9.0 build 130766 and all later versions of Cortex XSOAR.</span><br>"
}
],
"value":"This issue is fixed in Cortex XSOAR engine software available in Cortex XSOAR 6.9.0 build 130766 and all later versions of Cortex XSOAR.\n"
}
],
"credits":[
{
"lang":"en",
"value":"Palo Alto Networks thanks Olivier Caillault for discovering and reporting this issue."