7.8
CVSSv3

CVE-2019-3691

Published: 23/01/2020 Updated: 31/01/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local malicious users to escalate privileges from user munge to root. This issue affects: SUSE Linux Enterprise Server 15 munge versions before 0.5.13-4.3.1. openSUSE Factory munge versions before 0.5.13-6.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse munge