2024-12-08 03:06:42 +00:00

60 lines
2.0 KiB
JSON

{
"id": "CVE-2024-9875",
"sourceIdentifier": "psirt@okta.com",
"published": "2024-11-21T09:54:49.903",
"lastModified": "2024-11-21T13:57:24.187",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. To remediate this vulnerability, upgrade the Okta Privileged Access server agent (SFTD) to version 1.87.1 or greater."
},
{
"lang": "es",
"value": "Las versiones 1.82.0 a 1.84.0 de Okta Privileged Access server agent (SFTD) se ven afectadas por una vulnerabilidad de escalada de privilegios cuando la funci\u00f3n de paquetes de comandos sudo est\u00e1 habilitada. Para solucionar esta vulnerabilidad, actualice el agente de servidor de acceso privilegiado de Okta (SFTD) a la versi\u00f3n 1.87.1 o posterior."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "psirt@okta.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 1.8,
"impactScore": 5.2
}
]
},
"weaknesses": [
{
"source": "psirt@okta.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"references": [
{
"url": "https://help.okta.com/asa/en-us/content/topics/releasenotes/advanced-server-access-release-notes.htm",
"source": "psirt@okta.com"
}
]
}