The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the root user. The risk has been accepted by the vendor and won't be fixed in the near future.
References
Configurations
No configuration.
History
03 Nov 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
12 Dec 2024, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| Summary |
|
11 Dec 2024, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-12-11 16:15
Updated : 2025-11-03 22:16
NVD link : CVE-2024-28139
Mitre link : CVE-2024-28139
CVE.ORG link : CVE-2024-28139
JSON object : View
Products Affected
No product.
CWE
CWE-250
Execution with Unnecessary Privileges
