VDB
CVE-2021-31997
CVE-2021-31997
PUBLISHED
CVSS 6.8 MEDIUM
Reported by suse · Published June 10, 2021
A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local attackers to escalate from users postorius or postorius-admin to root. This issue affects: openSUSE Leap 15.2 python-postorius version 1.3.2-lp152.1.2 and prior versions. openSUSE Factory python-postorius version 1.3.4-2.1 and prior versions.
Risk Scores
CVSS 3.1
6.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openSUSE | Leap 15.2 | python-postorius |
| openSUSE | Factory | python-postorius |
| openSUSE | Leap 15.2 | * |
| openSUSE | Factory | python-postorius |
Timeline
- Jun 10, 2021 CVE Published
- Jun 11, 2021 EPSS Score
- Aug 12, 2021 EPSS Score
- Oct 12, 2021 EPSS Score
- Dec 11, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 12, 2022 EPSS Score
- Jun 12, 2022 EPSS Score
- Aug 13, 2022 EPSS Score
- Oct 12, 2022 EPSS Score
- Dec 12, 2022 EPSS Score