VDB

CVE-2024-48990

CVE-2024-48990 PUBLISHED CVSS 7.800000190734863 HIGH

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.

EPSS 20.45% · 97.3th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
20.45%
97.3th percentile

Affected Products

VendorProductVersions
needrestart_projectneedrestart0, 0
needrestart_projectneedrestart0, 0, 0
needrestartneedrestart0, 0

Timeline

  • Nov 19, 2024 Coalition ESS Score
  • Nov 19, 2024 Coalition ESS Score
  • Nov 19, 2024 CVE Published
  • Nov 20, 2024 EPSS Score
  • Nov 20, 2024 Coalition ESS Score
  • Nov 20, 2024 Coalition ESS Score
  • Nov 20, 2024 PoC Published
  • Nov 21, 2024 PoC Published
  • Nov 22, 2024 PoC Published
  • Nov 22, 2024 PoC Published
  • Nov 22, 2024 PoC Published
  • Nov 22, 2024 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›