Impact
A site user can prepare a malicious site and get local root permissions if the root user then runs
certain omd command for this site.
Affected omd commands are:
omd cp <site>
omd mv <site>
omd disable <site>
omd update <site>
Patches
A fix is available with the daily build omd-5.61.20260409-labs-edition and the not yet released stable version omd-5.70-labs-edition.
Workarounds
Do not run the omd commands mentioned above as root for untrusted sites.
References
Impact
A site user can prepare a malicious site and get local root permissions if the root user then runs
certain
omdcommand for this site.Affected omd commands are:
omd cp <site>omd mv <site>omd disable <site>omd update <site>Patches
A fix is available with the daily build
omd-5.61.20260409-labs-editionand the not yet released stable versionomd-5.70-labs-edition.Workarounds
Do not run the
omdcommands mentioned above as root for untrusted sites.References