CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user.
History

Fri, 20 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2024-01-22T13:53:35.745Z

Updated: 2025-06-20T18:33:37.646Z

Reserved: 2024-01-22T13:33:26.500Z

Link: CVE-2020-36771

cve-icon Vulnrichment

Updated: 2024-08-04T17:37:07.145Z

cve-icon NVD

Status : Modified

Published: 2024-01-22T14:15:07.530

Modified: 2025-06-20T19:15:20.827

Link: CVE-2020-36771

cve-icon Redhat

No data.