CVE-2021-32000: clone-master-clean-up: dangerous file system operations
A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3 clone-master-clean-up version 1.6-4.6.1 and prior versions. SUSE Linux Enterprise Server 15 SP1 clone-master-clean-up version 1.6-3.9.1 and prior versions. openSUSE Factory clone-master-clean-up version 1.6-1.4 and prior versions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-32000.
What is the severity of CVE-2021-32000?
The severity of CVE-2021-32000 is high with a CVSS score of 7.1.
Which software versions are affected by CVE-2021-32000?
CVE-2021-32000 affects SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1, and SUSE openSUSE Factory.
How does CVE-2021-32000 vulnerability work?
CVE-2021-32000 is a Symbolic Link (Symlink) Following vulnerability that allows local attackers to delete arbitrary files by exploiting the clone-master-clean-up.sh script in clone-master-clean-up.
Is there a fix or patch available for CVE-2021-32000?
Yes, a fix for CVE-2021-32000 is available. It is recommended to update to the latest version of the affected software.