CVE-2010-2022 describes a vulnerability in jail.c within FreeBSD 8.0 and 8.1-PRERELEASE. When specific options are omitted, this flaw allows local users to bypass intended restrictions on the current working directory, potentially leading to unauthorized reading, modification, or creation of arbitrary files. The vulnerability has a low CVSS score of 3.3, indicating a local attack vector with medium access complexity and partial impact on confidentiality and integrity. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While it has received minimal community discussion, it is not on the KEV catalog or Hot List, suggesting a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:8.0:*:*:*:*:*:*:* | ||
8.1-prereleaseCPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:8.1-prerelease:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.