Opendoas Project maintains a focused privilege-escalation and sudo-replacement utility with a narrow product scope but significant presence in Unix-like systems where elevated-privilege operations are required. The durable signal centers on the product's privileged execution context and recurring weaknesses in privilege management, resource initialization, and state-cleanup patterns, which are inherent risks in setuid tools. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opendoas Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25016HIGH In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules | Jan 28, 2021 | 8.8 | 27 | NO | NO |
CVE-2023-28339HIGH OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI is unavailable in OpenBSD 6.0 | Mar 14, 2023 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opendoas Project.
Media articles that mention a CVE ID that affects a product developed by Opendoas Project — matched by CVE ID, not by vendor name.