PT-2021-3364 · Opensuse · Opensuse Leap

Matthias Gerstner

·

Published

2021-02-17

·

Updated

2023-06-22

·

CVE-2021-25322

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions python-HyperKitty versions prior to 1.3.4-5.1 openSUSE Leap 15.2 python-HyperKitty version 1.3.2-lp152.2.3.1 and prior versions
Description The issue is related to a UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty, which allows local attackers to escalate privileges from the user hyperkitty or hyperkitty-admin to root. This vulnerability is associated with the implementation of the hyperkitty-permissions.sh script in the HyperKitty web interface for accessing Mailman archives.
Recommendations For openSUSE Leap 15.2 python-HyperKitty version 1.3.2-lp152.2.3.1 and prior versions, update to a version later than 1.3.2-lp152.2.3.1. For openSUSE Factory python-HyperKitty versions prior to 1.3.4-5.1, update to a version later than 1.3.4-5.1. As a temporary workaround, consider restricting access to the hyperkitty-permissions.sh script until a patch is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2021-03210
CVE-2021-25322
OPENSUSE-SU-2024:11207-1

Affected Products

Opensuse Leap