Loading HuntDB...

GHSA-5x22-w79m-34gq

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the radiusd user.

Related CVEs

Key Information

GHSA ID
GHSA-5x22-w79m-34gq
Published
May 24, 2022 4:46 PM
Last Modified
March 21, 2024 3:33 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: November 24, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.