Skip to content
COOEY

EXPOSURES › CVE-2021-3560

CVE-2021-3560

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-05-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-3560 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Red Hat Polkit Incorrect Authorization Vulnerability

Red Hat Polkit contains an incorrect authorization vulnerability allowing privilege escalation through bypassing credential checks for D-Bus requests. This can enable remote code execution and should be patched immediately.

Shame score — The vulnerability allowed privilege escalation through bypassing credential checks, enabling remote code execution, and was actively exploited in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Red Hat OpenShift Service on AWS (ROSA)
Red Hat
In Process