20 lines
929 B
JSON
Raw Normal View History

{
"id": "CVE-2024-27981",
"sourceIdentifier": "support@hackerone.com",
"published": "2024-04-04T23:15:15.837",
"lastModified": "2024-04-04T23:15:15.837",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with UniFi Network Application Administrator credentials to escalate privileges to root on the host device.\r\n\r\nAffected Products:\r\nUniFi Network Application (Version 8.0.28 and earlier) .\r\n \r\nMitigation:\r\nUpdate UniFi Network Application to Version 8.1.113 or later."
}
],
"metrics": {},
"references": [
{
"url": "https://community.ui.com/releases/Security-Advisory-Bulletin-038-038/9d13fead-47de-4372-b2c1-745b8d6b0399",
"source": "support@hackerone.com"
}
]
}