CVE-2021-30462: Critical severity vesta control panel vulnerability
VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-30462?
CVE-2021-30462 is a vulnerability in VestaCP through version 0.9.8-24 that allows the admin user to escalate privileges to root due to a misconfiguration in the Sudo setup.
How severe is CVE-2021-30462?
CVE-2021-30462 has a severity rating of 7.2 which is considered critical.
How can I exploit CVE-2021-30462?
As a cybersecurity analyst, I cannot provide information or assistance on exploiting vulnerabilities. It is important to report vulnerabilities responsibly to the vendor for resolution.
How do I fix CVE-2021-30462?
To fix CVE-2021-30462, users should update VestaCP to a version that includes the necessary fix, which is version 0.9.8-25 or later.
Are there any references for CVE-2021-30462?
Yes, you can find more information about CVE-2021-30462 at the following link: https://ssd-disclosure.com/ssd-advisory-vestacp-lpe-vulnerabilities/