CVE-2021-41583
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
vpn-user-portal (aka eduVPN or Let's Connect!) before 2.3.14, as packaged for Debian 10, Debian 11, and Fedora, allows remote authenticated users to obtain OS filesystem access, because of the interaction of QR codes with an exec that uses the -r option. This can be leveraged to obtain additional VPN access.
Affected (1)
Products: Eduvpn: Vpn User Portal
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.3.2 to 2.3.14 |
| Running on/with | Platform Versions |
|---|---|
Debian Debian Linux | Version 10.0 |
Fedoraproject Fedora | All versions |
References (3)
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: nvd@nist.gov
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Timeline
No history available yet.