CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.
Score: 0.0
Priority: Unclassified
Score: 0.00487
Percentile:
0.64433
CVSS v3.1 Score: 9.8
Severity: CRITICAL