Vulnerability Details
Basic Information
| Title | Harden-Runner allows evasion of ‘disable-sudo’ policy |
|---|---|
| Type | github |
| Published | 2025-04-22T01:07:03 |
| Last Seen | 2025-04-22T03:43:33 |
| CVSS Score | 6.0 (MEDIUM) |
CVSS v3 Details
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | HIGH |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
CVE Information
| CVE IDs | CVE-2025-32955 |
|---|---|
| CWE | CWE-250, CWE-268, CWE-272 |
| Bulletin Family | software |
Description
Summary Harden-Runner includes a policy option disable-sudo to prevent the GitHub Actions runner user from using sudo. This is implemented by removing the runner user from the sudoers file. However, this control can be bypassed as the runner user,…
Impact Assessment
| Base Score | 6.0 |
|---|---|
| Severity | MEDIUM |