peter bassill · operator
$ cve CVE-2004-0318 JSON

CVE-2004-0318 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 4.2% (pctl 91)

Patch early

A public exploit exists.

Description

Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which could allow remote attackers within the local cluster to gain privileges.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS4.24% — more likely to be exploited than 91% of all CVEs
On CISA KEVno
Public exploityes
Published2004-11-23
Last modified2026-06-16

Affected (1)

VendorProduct
platformlsf

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD