CVE-2020-25582
moderate-risk
Published 2021-03-26
In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 when a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it using ptrace(2) before the current working directory is changed.
Do I need to act?
-
0.39% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.7/10
High
NETWORK
/ LOW complexity
Affected Products (12)
Affected Vendors
References (4)
Third Party Advisory
https://security.netapp.com/advisory/ntap-20210423-0003/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20210423-0003/
48
/ 100
moderate-risk
Severity
30/34 · Critical
Exploitability
1/34 · Minimal
Exposure
17/34 · Moderate