In Sudo through 1.8.29, the fact that a user has been blocked (e.g., by using the ! character in the shadow file instead of a password hash) is not considered, allowing an attacker (who has access to a Runas ALL sudoer account) to impersonate any blocked user. NOTE: The software maintainer believes that this CVE is not valid. Disabling local password authentication for a user is not the same as disabling all access to that user--the user may still be able to login via other means (ssh key, kerberos, etc). Both the Linux shadow(5) and passwd(1) manuals are clear on this. Indeed it is a valid use case to have local accounts that are _only_ accessible via sudo and that cannot be logged into with a password. Sudo 1.8.30 added an optional setting to check the _shell_ of the target user (not the encrypted password!) against the contents of /etc/shells but that is not the same thing as preventing access to users with an invalid password hash
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade sudo-debugsourceUpgrade sudo-debuginfoUpgrade sudo | Feb 5, 2021 | Dec 19, 2019 |
| Debian | — | Upgrade sudo | Jul 30, 2024 | Dec 19, 2019 |
| Huawei Euleros 2_0_sp2 | — | Upgrade sudo | Jun 17, 2020 | Dec 19, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade sudo | Apr 16, 2020 | Dec 19, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade sudo | Feb 24, 2020 | Dec 19, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade sudo | Feb 26, 2020 | Dec 19, 2019 |
| Oracle Solaris | — | Upgrade security/sudo to version 1.8.30-11.4.20.0.1.1.0 on Solaris 11.4 | Jan 19, 2021 | Dec 19, 2019 |
| Redhat Openshift | — | Upgrade redhat-coreos | Feb 3, 2021 | Dec 19, 2019 |
| Redhat_linux | — | Upgrade sudo-debugsourceUpgrade sudo-debuginfoUpgrade sudoNo solution exists | Feb 5, 2021 | Dec 19, 2019 |
| Ubuntu | — | Upgrade sudo | Nov 19, 2024 | Dec 19, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 19, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub