A UNIX Symbolic Link (Symlink) Following vulnerability in python-postorius of openSUSE Leap 15.2, Factory allows local attackers to escalate from users postorius or postorius-admin to root. This issue affects: openSUSE Leap 15.2 python-postorius version 1.3.2-lp152.1.2 and prior versions. openSUSE Factory python-postorius version 1.3.4-2.1 and prior versions.
2021-06-10T12:15:08.857
2024-11-21T06:06:40.843
Modified
CVSSv3.1: 6.8 (MEDIUM)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | opensuse | python-postorius | < 1.3.2-lp152.1.2 | Yes |
| Operating System | opensuse | leap | 15.2 | No |
| Application | opensuse | python-postorius | ≤ 1.3.4-2.1 | Yes |
| Application | opensuse | factory | - | No |