CVE-2021-31998
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/06/2021
Last modified:
24/06/2021
Description
A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root. This issue affects: SUSE Linux Enterprise Server 11-SP3 inn version inn-2.4.2-170.21.3.1 and prior versions. openSUSE Backports SLE-15-SP2 inn versions prior to 2.6.2. openSUSE Leap 15.2 inn versions prior to 2.6.2.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:opensuse:inn:*:*:*:*:*:*:*:* | 2.4.2-170.21.3.1 (including) | |
| cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-:*:* | ||
| cpe:2.3:a:opensuse:inn:*:*:*:*:*:*:*:* | 2.6.2 (excluding) | |
| cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:* | ||
| cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



