1"use strict";(self.webpackChunkspectro_cloud_docs=self.webpackChunkspectro_cloud_docs||[]).push([["12776"],{730012:function(e,t,s){s.r(t),s.d(t,{frontMatter:()=>n,toc:()=>d,default:()=>u,metadata:()=>i,assets:()=>c,contentTitle:()=>a});var i=JSON.parse('{"id":"security-bulletins/reports/vc-cve-2023-26604","title":"CVE-2023-26604","description":"Lifecycle of CVE-2023-26604","source":"@site/docs/docs-content/security-bulletins/reports/vc-cve-2023-26604.md","sourceDirName":"security-bulletins/reports","slug":"/security-bulletins/reports/vc-cve-2023-26604","permalink":"/security-bulletins/reports/vc-cve-2023-26604","draft":false,"unlisted":false,"editUrl":"https://github.com/spectrocloud/librarium/blob/master/docs/docs-content/security-bulletins/reports/vc-cve-2023-26604.md","tags":[{"inline":true,"label":"security","permalink":"/tags/security"},{"inline":true,"label":"cve","permalink":"/tags/cve"}],"version":"current","lastUpdatedAt":null,"frontMatter":{"sidebar_label":"CVE-2023-26604","title":"CVE-2023-26604","description":"Lifecycle of CVE-2023-26604","sidebar_class_name":"hide-from-sidebar","hide_table_of_contents":false,"toc_max_heading_level":2,"tags":["security","cve"]},"sidebar":"docSidebar","previous":{"title":"CVE-2023-24540","permalink":"/security-bulletins/reports/vc-cve-2023-24540"},"next":{"title":"CVE-2023-27534","permalink":"/security-bulletins/reports/vc-cve-2023-27534"}}'),r=s(474848),l=s(884429);let n={sidebar_label:"CVE-2023-26604",title:"CVE-2023-26604",description:"Lifecycle of CVE-2023-26604",sidebar_class_name:"hide-from-sidebar",hide_table_of_contents:!1,toc_max_heading_level:2,tags:["security","cve"]},a,c={},d=[{value:"CVE Details",id:"cve-details",level:2},{value:"Initial Publication",id:"initial-publication",level:2},{value:"Last Update",id:"last-update",level:2},{value:"Third Party Dependency",id:"third-party-dependency",level:2},{value:"NIST CVE Summary",id:"nist-cve-summary",level:2},{value:"CVE Severity",id:"cve-severity",level:2},{value:"Our Official Summary",id:"our-official-summary",level:2},{value:"Status",id:"status",level:2},{value:"Affected Products & Versions",id:"affected-products--versions",level:2},{value:"Revision History",id:"revision-history",level:2}];function o(e){let t={a:"a",h2:"h2",p:"p",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",...(0,l.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(t.h2,{id:"cve-details",children:"CVE Details"}),"\n",(0,r.jsxs)(t.p,{children:["Visit the official vulnerability details page for ",(0,r.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2023-26604",children:"CVE-2023-26604"})," to learn more."]}),"\n",(0,r.jsx)(t.h2,{id:"initial-publication",children:"Initial Publication"}),"\n",(0,r.jsx)(t.p,{children:"10/25/2024"}),"\n",(0,r.jsx)(t.h2,{id:"last-update",children:"Last Update"}),"\n",(0,r.jsx)(t.p,{children:"06/24/2025"}),"\n",(0,r.jsx)(t.h2,{id:"third-party-dependency",children:"Third Party Dependency"}),"\n",(0,r.jsx)(t.p,{children:"libsystemd0"}),"\n",(0,r.jsx)(t.h2,{id:"nist-cve-summary",children:"NIST CVE Summary"}),"\n",(0,r.jsx)(t.p,{children:'systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo, because less executes as root when the terminal size is too small to show the complete systemctl output.'}),"\n",(0,r.jsx)(t.h2,{id:"cve-severity",children:"CVE Severity"}),"\n",(0,r.jsx)(t.p,{children:(0,r.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2023-26604",children:"7.8"})}),"\n",(0,r.jsx)(t.h2,{id:"our-official-summary",children:"Our Official Summary"}),"\n",(0,r.jsx)(t.p,{children:'A vulnerability was found in the systemd package. The systemd package does not adequately block local privilege escalation for some Sudo configurations, for example, plausible sudoers\nfiles, in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other programs may be launched from the less program. This\nissue presents a substantial security risk when running systemctl from Sudo because less executes as root when the terminal size is too small to show the complete systemctl output.'}),"\n",(0,r.jsx)(t.p,{children:"This is reported on a few of the third party images for which an upstream fix is not available. Probability of exploitation is less likely as attackers need privileged access to these\ncontainers and sufficient controls are in place to prevent that. We will wait for the upstream fix to become available."}),"\n",(0,r.jsx)(t.h2,{id:"status",children:"Status"}),"\n",(0,r.jsx)(t.p,{children:"Ongoing"}),"\n",(0,r.jsx)(t.h2,{id:"affected-products--versions",children:"Affected Products & Versions"}),"\n",(0,r.jsxs)(t.table,{children:[(0,r.jsx)(t.thead,{children:(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.th,{children:"Version"}),(0,r.jsx)(t.th,{children:"Palette Enterprise"}),(0,r.jsx)(t.th,{children:"Palette Enterprise Airgap"}),(0,r.jsx)(t.th,{children:"VerteX"}),(0,r.jsx)(t.th,{children:"VerteX Airgap"})]})}),(0,r.jsxs)(t.tbody,{children:[(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.6.41"}),(0,r.jsx)(t.td,{children:"\u2705 No Impact"}),(0,r.jsx)(t.td,{children:"\u2705 No Impact"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.5.22"}),(0,r.jsx)(t.td,{children:"\u2705 No Impact"}),(0,r.jsx)(t.td,{children:"\u2705 No Impact"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,r.jsxs)(t.tr,{children:[(0,r.jsx)(t.td,{children:"4.4.20"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,r.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]})]})]}),"\n",(0,r.jsx)(t.h2,{id:"revision-history",children:"Revision History"}),"\n",(0,r.jsx)(t.p,{children:"No revisions available."})]})}function u(e={}){let{wrapper:t}={...(0,l.R)(),...e.components};return t?(0,r.jsx)(t,{...e,children:(0,r.jsx)(o,{...e})}):o(e)}},884429:function(e,t,s){s.d(t,{R:()=>n,x:()=>a});var i=s(296540);let r={},l=i.createContext(r);function n(e){let t=i.useContext(l);return i.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function a(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:n(e.components),i.createElement(l.Provider,{value:t},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.