It was found that polkit could be tricked into bypassing...
High severity
Unreviewed
Published
Feb 17, 2022
to the GitHub Advisory Database
•
Updated Jun 27, 2024
Description
Published by the National Vulnerability Database
Feb 16, 2022
Published to the GitHub Advisory Database
Feb 17, 2022
Last updated
Jun 27, 2024
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
References