Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-10737

17
FAUCET Score

CVE-2020-10737 describes a race condition in the mkhomedir tool within the oddjob package (versions prior to 0.34.5 and 0.34.6). This flaw allows a privileged attacker to create a symlink during home directory creation, leading to an unprivileged user gaining ownership of an arbitrary target folder. The vulnerability has a CVSS score of 6.3 (Medium), indicating a local attack with high complexity, requiring high privileges and user interaction, but resulting in high impact to confidentiality, integrity, and availability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.34.5CPE matchmatch criteria
cpe:2.3:a:redhat:oddjob:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.3MEDIUM

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.3
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 64th percentile among its peer group of 74 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: oddjob-0:0.34.5-3.el8
View patch
redhatvendor investigatingvia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: oddjob

Vendor Advisories (1)

redhatCVE-2020-10737Moderate

oddjob: race condition in oddjob_selinux_mkdir function in mkhomedir.c can lead to symlink attack

May 7, 2020

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingVendor Advisory
pagure.io / oddjob/c/10b8aaa1564b723a005b53acc069df71313f4cac
PatchThird Party Advisory