External Control of File Name or Path in Crosswork Network Services Orchestrator - CVE-2024-20366
Published: May 16, 2024
Crosswork Network Services Orchestrator
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a user-controlled search path is used to locate executable files within the Tail-f High Availability Cluster Communications (HCC) function. A local user can send a specially crafted HTTP request and execute arbitrary code with elevated privileges.