Vulnerability Details CVE-2021-20001
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-20001
-
cpe:2.3:a:skolelinux:debian-edu-config:-
-
cpe:2.3:a:skolelinux:debian-edu-config:1.818
-
cpe:2.3:a:skolelinux:debian-edu-config:1.929
-
cpe:2.3:a:skolelinux:debian-edu-config:2.10.65
-
cpe:2.3:a:skolelinux:debian-edu-config:2.11.10
-
cpe:2.3:a:skolelinux:debian-edu-config:2.11.17
-
cpe:2.3:a:skolelinux:debian-edu-config:2.11.18
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.1
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.10
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.11
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.12
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.13
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.14
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.15
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.2
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.3
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.4
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.5
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.6
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.7
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.8
-
cpe:2.3:a:skolelinux:debian-edu-config:2.12.9
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:debian:debian_linux:11.0
-
cpe:2.3:o:debian:debian_linux:9.0