Lucene search

K
cvelistSuseCVELIST:CVE-2022-21950
HistorySep 07, 2022 - 12:00 a.m.

CVE-2022-21950 canna: unsafe handling of /tmp/.iroha_unix directory

2022-09-0700:00:00
CWE-284
suse
www.cve.org
cve-2022-21950
canna
unsafe handling
/tmp/.iroha_unix directory
improper access control
systemd service
opensuse backports
sle-15-sp3
sle-15-sp4
local users
hijack
unix domain socket
vulnerability
opensuse factory
package deletion

5.3 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local users to hijack the UNIX domain socket This issue affects: openSUSE Backports SLE-15-SP3 canna versions prior to canna-3.7p3-bp153.2.3.1. openSUSE Backports SLE-15-SP4 canna versions prior to 3.7p3-bp154.3.3.1. openSUSE Factory was also affected. Instead of fixing the package it was deleted there.

CNA Affected

[
  {
    "vendor": "openSUSE",
    "product": "openSUSE Backports SLE-15-SP3",
    "versions": [
      {
        "version": "canna",
        "status": "affected",
        "lessThan": "canna-3.7p3-bp153.2.3.1",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "openSUSE",
    "product": "openSUSE Backports SLE-15-SP4",
    "versions": [
      {
        "version": "canna",
        "status": "affected",
        "lessThan": "3.7p3-bp154.3.3.1",
        "versionType": "custom"
      }
    ]
  }
]

5.3 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVELIST:CVE-2022-21950