You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The PATH environment variable should always be set to an absolute directory pathing. Referencing the current directory is considered bad practice as it can lead to unintentional file execution or malicious abuse, as with CVE-2021-4034 (pkexec privilege escalation).
Additional Details
Detail
Value
Type
Templated Match
Category
Privilege Escalation
Apply Risk to Entities
device_hostname, user_username
Signal Name
PATH Variable Set to Current Directory
Summary Expression
User: {{user_username}} executed a command on host {{device_hostname}} to set the PATH variable