CVE-2020-12850

Source
https://cve.org/CVERecord?id=CVE-2020-12850
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-12850.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-12850
Published
2020-06-11T02:15:10Z
Modified
2026-07-08T20:58:15Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF (such as version 2.0.3) have a looser policy restriction allowing the “pydio” user to execute any privileged command using sudo. In version 2.0.4 of the appliance, the user pydio is responsible for running all the services and binaries that are contained in the Pydio Cells web application package, such as mysqld, cells, among others. This user has privileges restricted to run those services and nothing more.

References

Affected packages

Git / github.com/pydio/cells

Affected ranges

Type
GIT
Repo
https://github.com/pydio/cells
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:pydio:cells:2.0.4:*:*:*:enterprise:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.0.4"
        },
        {
            "last_affected": "2.0.4"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

2.*
2.0.4
v2.*
v2.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-12850.json"