CVE-2018-14348 affects libcgroup versions up to and including 0.41, specifically impacting Debian and Fedora distributions. The vulnerability stems from the cgroup daemon (cgred) creating the /var/log/cgred file with world-readable permissions (0666), regardless of the system's umask setting. This misconfiguration allows for information disclosure, as sensitive data within the log file can be accessed by unauthorized users. Rated with a CVSS score of 8.1 (High), this vulnerability has a low attack complexity and requires low privileges for an attacker to exploit, leading to a high impact on confidentiality. While it has a low EPSS score, indicating a low probability of exploitation, its FAUCET Risk Score is 63/100. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.41CPE matchmatch criteria | cpe:2.3:a:libcgroup_project:libcgroup:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
28CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2018-14348
Aug 11, 2020libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask leading to disclosure of information.
Aug 14, 2018libcgroup: cgrulesengd creates log files with insecure permissions
Jul 25, 2018