Vulnerability CVE-2022-2104


Published: 2022-06-24

Description:
The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh and /bin/bash).

Type:

CWE-269

(Improper Privilege Management)

 References:
https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-03

Copyright 2026, cxsecurity.com

 

Back to Top