CVE-2022-31252
CVSS V2 None
CVSS V3 Medium 4.4
Description
A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE Leap Micro 5.2 did not consider group writable path components, allowing local attackers with access to a group what can write to a location included in the path to a privileged binary to influence path resolution. This issue affects: SUSE Linux Enterprise Server 12-SP5 permissions versions prior to 20170707. openSUSE Leap 15.3 permissions versions prior to 20200127. openSUSE Leap 15.4 permissions versions prior to 20201225. openSUSE Leap Micro 5.2 permissions versions prior to 20181225.
Overview
- CVE ID
- CVE-2022-31252
- Assigner
- meissner@suse.de
- Vulnerability Status
- Analyzed
- Published Version
- 2022-10-06T18:16:01
- Last Modified Date
- 2022-11-07T20:20:15
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:o:opensuse:leap:15.3:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:opensuse:leap:15.4:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:opensuse:leap_micro:5.2:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:*:*:*:* | 1 | OR |
CVSS Version 3
- Version
- 3.1
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Vector
- LOCAL
- Attack Compatibility
- LOW
- Privileges Required
- LOW
- User Interaction
- NONE
- Scope
- UNCHANGED
- Confidentiality Impact
- LOW
- Availability Impact
- NONE
- Base Score
- 4.4
- Base Severity
- MEDIUM
- Exploitability Score
- 1.8
- Impact Score
- 2.5
References
Reference URL | Reference Tags |
---|---|
https://bugzilla.suse.com/show_bug.cgi?id=1203018 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2022-31252 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31252 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-10-06 19:00:55 | Added to TrackCVE | |||
2022-12-07 05:33:01 | security@suse.com | meissner@suse.de | CVE Assigner | updated |
2022-12-07 05:33:01 | 2022-10-06T18:16Z | 2022-10-06T18:16:01 | CVE Published Date | updated |
2022-12-07 05:33:01 | 2022-11-07T20:20:15 | CVE Modified Date | updated | |
2022-12-07 05:33:01 | Analyzed | Vulnerability Status | updated |