Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hmq6-cxg5-4f9w

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The image creation configuration in aaa_base before 16.26.1 for openSUSE 13.1 KDE adds the root user to the "users" group when installing from a live image, which allows local users to obtain sensitive information and possibly have other unspecified impacts, as demonstrated by reading /etc/shadow.

The image creation configuration in aaa_base before 16.26.1 for openSUSE 13.1 KDE adds the root user to the "users" group when installing from a live image, which allows local users to obtain sensitive information and possibly have other unspecified impacts, as demonstrated by reading /etc/shadow.

EPSS

Процентиль: 16%
0.00052
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
около 12 лет назад

The image creation configuration in aaa_base before 16.26.1 for openSUSE 13.1 KDE adds the root user to the "users" group when installing from a live image, which allows local users to obtain sensitive information and possibly have other unspecified impacts, as demonstrated by reading /etc/shadow.

EPSS

Процентиль: 16%
0.00052
Низкий

Дефекты

CWE-200