VDB

CVE-2024-48992

CVE-2024-48992 PUBLISHED CVSS 7.800000190734863 HIGH

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.

EPSS 7.57% · 94.2th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
7.57%
94.2th percentile

Affected Products

VendorProductVersions
needrestart_projectneedrestart0, 0, 0
needrestart_projectneedrestart0, 0
needrestartneedrestart0, 0

Timeline

  • Nov 19, 2024 Coalition ESS Score
  • Nov 19, 2024 CVE Published
  • Nov 20, 2024 EPSS Score
  • Nov 21, 2024 PoC Published
  • Nov 22, 2024 PoC Published
  • Nov 22, 2024 PoC Published
  • Nov 22, 2024 PoC Published
  • Nov 22, 2024 PoC Published
  • Nov 23, 2024 PoC Published
  • Nov 24, 2024 PoC Published
  • Nov 24, 2024 PoC Published
  • Nov 24, 2024 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›