Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2020-8027— openldap uses fixed paths in /tmp

Quick assessment

Affected
SUSE SUSE Linux Enterprise Server 15-LTSS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

openSUSE是德国SUSE公司的一套基于Linux的自由操作系统与开源社区项目。 SUSE LE 15版本存在安全漏洞,该漏洞源于openldap_update_modules_path.sh模块使用/tmp中的固定路径。

CVSS 7.3 · High EPSS 0.30% · P21

Possible ATT&CK Techniques 1 AI

T1222.001 · Windows Permissions
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2020-8027

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
openldap uses fixed paths in /tmp
Source: CVE Program / CVE List V5
Vulnerability Description
A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This issue affects: SUSE Linux Enterprise Server 15-LTSS openldap2 versions prior to 2.4.46-9.37.1. SUSE Linux Enterprise Server for SAP 15 openldap2 versions prior to 2.4.46-9.37.1. openSUSE Leap 15.1 openldap2 versions prior to 2.4.46-lp151.10.18.1. openSUSE Leap 15.2 openldap2 versions prior to 2.4.46-lp152.14.9.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不安全的临时文件
Source: CVE Program / CVE List V5
Vulnerability Title
SUSE openSUSE 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
openSUSE是德国SUSE公司的一套基于Linux的自由操作系统与开源社区项目。 SUSE LE 15版本存在安全漏洞,该漏洞源于openldap_update_modules_path.sh模块使用/tmp中的固定路径。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
SUSE SUSE Linux Enterprise Server 15-LTSS openldap2 ~ 2.4.46-9.37.1 -
SUSE SUSE Linux Enterprise Server for SAP 15 openldap2 ~ 2.4.46-9.37.1 -
openSUSE openSUSE Leap 15.1 openldap2 ~ 2.4.46-lp151.10.18.1 -
openSUSE openSUSE Leap 15.2 openldap2 ~ 2.4.46-lp152.14.9.1 -

II. Public POCs for CVE-2020-8027

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-8027

请登录查看更多情报信息。

Vendor Advisories for CVE-2020-8027 (1)

Same Patch Batch · SUSE · 2021-02-11 · 3 CVEs total

CVE-2020-8030 3.6 LOW skuba: Insecure /tmp usage when joining node to cluster
CVE-2020-8029 2.9 LOW skuba: Insecure handling of private key

IV. Related Vulnerabilities

V. Comments for CVE-2020-8027

No comments yet


Leave a comment