Weak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a local unprivileged user in the gromox group to have the PAM stack execute arbitrary code upon loading the Gromox PAM module.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "0.5"
},
{
"fixed": "1.x"
},
{
"fixed": "1.28"
}
],
"source": "DESCRIPTION"
}
],
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/37xxx/CVE-2022-37030.json"
}