AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-19232

HIGH · CVSS 7.5 EPSS 3.29%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-12-19 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. See the original NVD description below for full technical details.

CVE
CVE-2019-19232
Severity
HIGH
CVSS
7.5
EPSS
3.29%

Original NVD Description

In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a command via sudo as a user not present in the local password database is an intentional feature. Because this behavior surprised some users, sudo 1.8.30 introduced an option to enable/disable this behavior with the default being disabled. However, this does not change the fact that sudo was behaving as intended, and as documented, in earlier versions

Related CVEs

Other vulnerabilities affecting the same vendor(s)