Privilege Escalation Vulnerability in Logpoint 7.1 Before 7.1.2
CVE-2022-48685
6.7MEDIUM
What is CVE-2022-48685?
A security flaw was identified in Logpoint versions prior to 7.1.2, where the cron job 'clean_secbi_old_logs' is writable by all users but runs with root privileges. This configuration allows malicious users to manipulate the cron job script, potentially leading to unauthorized actions or privilege escalation within the system. Organizations using affected versions of Logpoint should implement immediate security measures to restrict access to the cron file and monitor user activities.
