Description


atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modify any file. Authentication is not forcibly enabled in the default configuration.

Related CPE's


Vulnerable

o

openatom

openeuler

3

Weaknesses



CWE-306

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.8 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-03-11T17:15:21.320Z

4 years ago

Last modified

2025-04-02T16:33:53.340Z

1 year ago