CVE-2020-24612

Source
https://cve.org/CVERecord?id=CVE-2020-24612
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-24612.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-24612
Downstream
Published
2020-08-24T21:15:15.877Z
Modified
2026-07-08T06:01:05.569493989Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allowed to read the user's U2F configuration file. If configured with the nouserok option (the default when configured by the authselect tool), and that file cannot be read, the second factor is disabled. An attacker with only the knowledge of the password can then log in, bypassing 2FA.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:fedoraproject:selinux-policy:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "fedoraproject:selinux-policy",
            "extracted_events": [
                {
                    "introduced": "3.14"
                },
                {
                    "last_affected": "2020-08-24"
                }
            ]
        },
        {
            "extracted_events": [
                {
                    "introduced": "3.14"
                },
                {
                    "fixed": "2020-08-24"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/fedora-selinux/selinux-policy

Affected ranges

Type
GIT
Repo
https://github.com/fedora-selinux/selinux-policy
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-24612.json"