Description
An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue affects Client Connector: before 1.4.0.105
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Any version before 1.4.0.105
Credits
Tesla Red Team
References
help.zscaler.com/...lient-connector-app-release-summary-2023
help.zscaler.com/...lient-connector-app-release-summary-2023