- Description
- OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- cups
CVSS 3.1
- Type
- Primary
- Base score
- 6.3
- Impact score
- 4.2
- Exploitability score
- 2.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
- Severity
- MEDIUM
- security-advisories@github.com
- CWE-863
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8A2A4507-B2D7-43B8-B008-6EC2F5053FA9",
"versionEndIncluding": "2.4.16",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]