First published: Thu Jul 08 2021(Updated: )
A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3 clone-master-clean-up version 1.6-4.6.1 and prior versions. SUSE Linux Enterprise Server 15 SP1 clone-master-clean-up version 1.6-3.9.1 and prior versions. openSUSE Factory clone-master-clean-up version 1.6-1.4 and prior versions.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Java SE | =12-sp3 | |
Oracle Java SE | =15-sp1 | |
SUSE openSUSE Factory |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-32000.
The severity of CVE-2021-32000 is high with a CVSS score of 7.1.
CVE-2021-32000 affects SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1, and SUSE openSUSE Factory.
CVE-2021-32000 is a Symbolic Link (Symlink) Following vulnerability that allows local attackers to delete arbitrary files by exploiting the clone-master-clean-up.sh script in clone-master-clean-up.
Yes, a fix for CVE-2021-32000 is available. It is recommended to update to the latest version of the affected software.