CWE-243

Creation of chroot Jail Without Changing Working Directory

High

Description

The product uses the chroot() system call to create a jail, but does not change the working directory afterward. This does not prevent access to files outside of the jail.

Potential Impact

Detection Methods

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-243 vulnerabilities in your codebase.

Get Security Assessment