← Back to CVE List

CVE-2019-3842

Published: 2019-04-09T21:29Z
Last Modified: 2024-11-21T04:42Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the "allow_active" element rather than "allow_any". > MITRE Terms of Use apply – see LICENSE‑MITRE.txt