From 8457507055b402a1f245017489ef4c70e24f724a Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Wed, 6 Nov 2024 12:57:53 +0000 Subject: [ GLSA 202411-03 ] Ubiquiti UniFi: Privilege Escalation Bug: https://bugs.gentoo.org/941922 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202411-03.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 glsa-202411-03.xml diff --git a/glsa-202411-03.xml b/glsa-202411-03.xml new file mode 100644 index 00000000..3b801a33 --- /dev/null +++ b/glsa-202411-03.xml @@ -0,0 +1,42 @@ + + + + Ubiquiti UniFi: Privilege Escalation + A vulnerability has been discovered in Ubiquiti UniFi, which can lead to local privilege escalation. + unifi + 2024-11-06 + 2024-11-06 + 941922 + local + + + 8.5.6 + 8.5.6 + + + +

Ubiquiti UniFi is a Management Controller for Ubiquiti Networks UniFi APs.

+
+ +

A vulnerability has been discovered in Ubiquiti UniFi. Please review the CVE identifier referenced below for details.

+
+ +

The vulnerability allows a malicious actor with a local operational system user to execute high privilege actions on UniFi Network Server.

+
+ +

There is no known workaround at this time.

+
+ +

All Ubiquiti UniFi users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-wireless/unifi-8.5.6" + +
+ + CVE-2024-42028 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad