CVE-2023-6395 Details
Description
The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of proper sandboxing during the expansion and execution of Jinja2 templates, which may be included in certain configuration parameters. While the Mock documentation advises treating users added to the mock group as privileged, certain build systems invoking mock on behalf of users might inadvertently permit less privileged users to define configuration tags. These tags could then be passed as parameters to mock during execution, potentially leading to the utilization of Jinja2 templates for remote privilege escalation and the execution of arbitrary code as the root user on the build server.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 25, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| rpm-software-management mock | All versions |
CPE
Remediation
| |
| fedoraproject extra packages for enterprise linux | 7.0 8.0 9.0 |
CPE
Remediation
| |
| fedoraproject fedora | 38 39 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Oct 25, 2024 | CVE Modified | CISA-ADP |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 9, 2024 | CVE Modified | [email protected] |
| Jan 30, 2024 | CVE Modified | [email protected] |
| Jan 25, 2024 | Initial Analysis | [email protected] |
| Jan 16, 2024 | CVE Modified | [email protected] |
| Jan 16, 2024 | CVE Modified | [email protected] |
| Jan 16, 2024 | New CVE Received | [email protected] |