← back
CVE-2020-10737

CVE-2020-10737

CVSS 6.3 MEDIUMEPSS 0.3%CWE-362
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.3EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
27 May 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creation, mkhomedir copies the /etc/skel directory into the newly created home and changes its ownership to the home's user without properly checking the homedir path. This flaw allows an attacker to leverage this issue by creating a symlink point to a target folder, which then has its ownership transferred to the new home directory's unprivileged user.
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Affected products
Red Hat · oddjob

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →