CVE-2018-11116: High severity open edx vulnerability
DISPUTED OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call arbitrary methods (i.e., achieve ubus access over HTTP) that were only supposed to be accessible to a specific user, as demonstrated by the file, log, and service namespaces, potentially leading to remote Information Disclosure or Code Execution. NOTE: The developer disputes this as a vulnerability, indicating that rpcd functions appropriately.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-11116.
What is the severity of CVE-2018-11116?
The severity of CVE-2018-11116 is high with a score of 8.8.
What software is affected by CVE-2018-11116?
OpenWrt is affected by CVE-2018-11116.
How does CVE-2018-11116 work?
CVE-2018-11116 allows remote authenticated users to call arbitrary methods that were only supposed to be accessible to a specific user.
Are there any fixes or mitigations available for CVE-2018-11116?
At this time, there is no information available about fixes or mitigations for CVE-2018-11116. It is recommended to stay updated with the latest security patches and advisories from OpenWrt.