Skolelinux is an educational Linux distribution based on Debian that provides preconfigured school computing environments, with its vulnerability footprint concentrated in the debian-edu-config package that handles system configuration and defaults. The observed weakness classes center on incorrect default permissions and improper permission assignment for critical resources, reflecting the configuration and access-control surface area inherent to a system-hardening distribution. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Skolelinux over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20001CRITICAL It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/pub | Feb 11, 2022 | 9.8 | 32 | NO | NO |
CVE-2019-3467HIGH Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin serv | Dec 23, 2019 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Skolelinux.
Media articles that mention a CVE ID that affects a product developed by Skolelinux — matched by CVE ID, not by vendor name.