Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vulnerability whereby an authenticated attacker can elevate privileges and execute arbitrary code with SYSTEM privilege.  The vulnerability is caused by the product's implementation of OpenSSL's`OPENSSLDIR` parameter where it is set to a path accessible to low-privileged users.  The vulnerability has been remediated and fixed in version 4.5.5. 
Advisories
Source ID Title
EUVD EUVD EUVD-2024-16190 Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vulnerability whereby an authenticated attacker can elevate privileges and execute arbitrary code with SYSTEM privilege.  The vulnerability is caused by the product's implementation of OpenSSL's`OPENSSLDIR` parameter where it is set to a path accessible to low-privileged users.  The vulnerability has been remediated and fixed in version 4.5.5. 
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2024-08-22T14:59:24.319Z

Reserved: 2024-01-10T11:30:43.029Z

Link: CVE-2024-0394

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:49.644Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-03T14:15:13.170

Modified: 2024-11-21T08:46:29.437

Link: CVE-2024-0394

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses