6.5
CVSSv2

CVE-2019-25016

Published: 28/01/2021 Updated: 26/04/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A security issue has been found in OpenDoas prior to 6.8.1, where rules that allowed the user to execute any command would inherit the executing user's PATH instead of resetting it to a default PATH. Rules that limit the user to execute only a specific command are not affected by this and are only executed from the default PATH and with the PATH environment variable set to the safe default.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opendoas project opendoas

Vendor Advisories

A security issue has been found in OpenDoas before 681, where rules that allowed the user to execute any command would inherit the executing user's PATH instead of resetting it to a default PATH Rules that limit the user to execute only a specific command are not affected by this and are only executed from the default PATH and with the PATH envi ...