CVE-2021-23239 is a low-severity race condition vulnerability in the sudoedit personality of Sudo before version 1.9.5, affecting products like Debian and Fedora. A local, unprivileged user could potentially perform arbitrary directory-existence tests. With a CVSS score of 2.5, exploitation requires high attack complexity and offers limited impact, specifically low confidentiality and no integrity or availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage, indicating a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.32CPE matchmatch criteria | cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:* | ||
>= 1.9.0, < 1.9.5CPE matchmatch criteria | cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.
Jan 12, 2021sudo: possible directory existence test due to race condition in sudoedit
Jan 11, 2021