Executive brief
Unraid versions through 6.8.0 contain a remote code execution vulnerability due to the insecure use of the extract() PHP function. An unauthenticated attacker can exploit this to execute code as root, often by chaining it with CVE-2020-5849 for initial access.
Affected products
- Unraid Unraid up to and including 6.8.0
Timeline
- 2020-02-06: disclosed: Initial disclosure by Sysdream
- 2020-03-16: advisory: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV catalog entry date