CVE-2021-20001: Critical severity Skolelinux Debian-edu-config vulnerability
Published Feb 11, 2022
·Updated
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/publichtml), which could result in privilege escalation.
Affected Software
5 affected componentsFixes available
debian/debian-edu-config
2.10.65+deb10u82.11.56+deb11u42.11.56+deb11u32.12.322.12.37
Skolelinux Debian-edu-config<2.12.16
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Event History
Feb 11, 2022
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20001?
CVE-2021-20001 has a severity level that allows for privilege escalation due to insecure permissions on user web shares.
2
How do I fix CVE-2021-20001?
To fix CVE-2021-20001, update debian-edu-config to version 2.12.16 or later.
3
Which versions of debian-edu-config are affected by CVE-2021-20001?
Versions of debian-edu-config before 2.12.16 are affected by CVE-2021-20001.
4
What impact does CVE-2021-20001 have on Debian systems?
CVE-2021-20001 can result in unauthorized access to user web shares, leading to potential data exposure.
5
Is CVE-2021-20001 present in Debian Edu configurations?
Yes, CVE-2021-20001 specifically affects the Debian Edu blend configurations prior to version 2.12.16.