← Back to CVE List
Vulnerability Intelligence Report
Insights-client: unsafe handling of temporary files and directories

CVE-2023-3972

A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could create the /var/tmp/insights-client directory (owning the directory with read, write, and execute permissions) on the system. After the insights-client is registered by root, an attacker could then control the directory content that insights are using by putting malicious scripts into it and executing arbitrary code as root (trivially bypassing SELinux protections because insights processes are allowed to disable SELinux system-wide).

No Active Exploit Signals
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:0.26%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-379 ↗Creation of Temporary File in Directory with Insecure Permissions

Affected Products & Versions

Vendor Product Affected Versions
Red Hat Red Hat Enterprise Linux 7 0:3.1.9-1.el7_9 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8 0:3.2.2-1.el8_8 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions 0:3.2.3-1.el8_1 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support 0:3.2.3-1.el8_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.2 Telecommunications Update Service 0:3.2.3-1.el8_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions 0:3.2.3-1.el8_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:3.2.3-1.el8_4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service 0:3.2.3-1.el8_4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions 0:3.2.3-1.el8_4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support 0:3.2.2-1.el8_6 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9 0:3.2.2-1.el9_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9.0 Extended Update Support 0:3.2.2-1.el9_0 < * (unaffected)
Red Hat Red Hat Enterprise Linux 6 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.257%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2023-07-27T12:10:37
Published2023-11-01T15:54:52
Patch Date2023-11-01
Last Updated2026-04-06T14:29:37

LINK COPIED TO CLIPBOARD