CVE-2019-25016
Last modified
CVE-2019-25016 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user to execute specific commands were not affected by this issue.. EPSS estimates a 2.63% chance of exploitation in the next 30 days.
Description
In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user to execute specific commands were not affected by this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opendoas Project | Opendoas | >= 6.6, <= 6.8 |
References
- https://github.com/Duncaen/OpenDoas/commit/01c658f8c45cb92a343be5f32aa6da70b2032168Patch, Third Party Advisory
- https://github.com/Duncaen/OpenDoas/commit/d5acd52e2a15c36a8e06f9103d35622933aa422dPatch, Third Party Advisory
- https://github.com/Duncaen/OpenDoas/issues/45Exploit, Issue Tracking, Third Party Advisory
- https://github.com/Duncaen/OpenDoas/releases/tag/v6.8.1Release Notes, Third Party Advisory
- https://security.gentoo.org/glsa/202107-11Third Party Advisory
- https://github.com/Duncaen/OpenDoas/commit/01c658f8c45cb92a343be5f32aa6da70b2032168Patch, Third Party Advisory
- https://github.com/Duncaen/OpenDoas/commit/d5acd52e2a15c36a8e06f9103d35622933aa422dPatch, Third Party Advisory
- https://github.com/Duncaen/OpenDoas/issues/45Exploit, Issue Tracking, Third Party Advisory
- https://github.com/Duncaen/OpenDoas/releases/tag/v6.8.1Release Notes, Third Party Advisory
- https://security.gentoo.org/glsa/202107-11Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-25016?
How severe is CVE-2019-25016?
How do I fix CVE-2019-25016?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-25010An issue was discovered in the failure crate through 2019-11…9.8
- CVE-2019-25011NetBox through 2.6.2 allows an Authenticated User to conduct…5.4
- CVE-2019-25012The Webform Report project 7.x-1.x-dev for Drupal allows rem…7.5
- CVE-2019-25013The iconv feature in the GNU C Library (aka glibc or libc6) …5.9
- CVE-2019-25014A NULL pointer dereference was found in pkg/proxy/envoy/v2/d…6.5
- CVE-2019-25015LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS vi…5.4
- CVE-2019-25017An issue was discovered in rcp in MIT krb5-appl through 1.0.…5.9
- CVE-2019-25018In the rcp client in MIT krb5-appl through 1.0.3, malicious …7.5
- CVE-2019-25019LimeSurvey before 4.0.0-RC4 allows SQL injection via the par…9.8
- CVE-2019-2502Vulnerability in the MySQL Server component of Oracle MySQL …4.9
- CVE-2019-25020An issue was discovered in Scytl sVote 2.1. Because the sdm-…7.5
- CVE-2019-25021An issue was discovered in Scytl sVote 2.1. Due to the imple…7.5
Are you affected by CVE-2019-25016?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
