Opensuse Openldap2 vulnerabilities

3 known vulnerabilities affecting opensuse/openldap2.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2022-31253HIGHCVSS 7.8fixed in 2.6.3-404.12022-11-09
CVE-2022-31253 [HIGH] CWE-426 CVE-2022-31253: A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with c A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with control of the ldap user or group to change ownership of arbitrary directory entries to this user/group, leading to escalation to root. This issue affects: openSUSE Factory openldap2 versions prior to 2.6.3-404.1.
nvd
CVE-2020-8027MEDIUMCVSS 6.6fixed in 2.4.46-9.37.1fixed in 2.4.46-lp151.10.18.1+1 more2021-02-11
CVE-2020-8027 [HIGH] CWE-377 CVE-2020-8027: A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE L A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This issue affects: SUSE Linux Enterprise Server 15-LTSS openldap2 versions prior
nvd
CVE-2020-8023HIGHCVSS 7.8fixed in 2.4.41-18.71.2fixed in 2.4.26-0.74.13.1+2 more2020-09-01
CVE-2020-8023 [HIGH] CWE-349 CVE-2020-8023: A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of ope A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SECURITY, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux
nvd