// For flags

CVE-2022-21950

canna: unsafe handling of /tmp/.iroha_unix directory

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local users to hijack the UNIX domain socket This issue affects: openSUSE Backports SLE-15-SP3 canna versions prior to canna-3.7p3-bp153.2.3.1. openSUSE Backports SLE-15-SP4 canna versions prior to 3.7p3-bp154.3.3.1. openSUSE Factory was also affected. Instead of fixing the package it was deleted there.

Una vulnerabilidad de Control de Acceso inapropiado en el servicio systemd de cana en openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 permite a usuarios locales secuestrar el socket de dominio UNIX Este problema afecta a: openSUSE Backports SLE-15-SP3 versiones de canna anteriores a canna-3.7p3-bp153.2.3.1. openSUSE Backports SLE-15-SP4 versiones de canna anteriores a 3.7p3-bp154.3.3.1. openSUSE Factory también está afectado. En lugar de arreglar el paquete fue eliminado allí

*Credits: Matthias Gerstner from SUSE
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-12-16 CVE Reserved
  • 2022-09-07 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-284: Improper Access Control
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Opensuse
Search vendor "Opensuse"
Canna
Search vendor "Opensuse" for product "Canna"
< 3.7p3-bp153.2.3.1
Search vendor "Opensuse" for product "Canna" and version " < 3.7p3-bp153.2.3.1"
-
Affected
in Opensuse
Search vendor "Opensuse"
Backports Sle
Search vendor "Opensuse" for product "Backports Sle"
15.0
Search vendor "Opensuse" for product "Backports Sle" and version "15.0"
sp3
Safe
Opensuse
Search vendor "Opensuse"
Canna
Search vendor "Opensuse" for product "Canna"
< 3.7p3-bp154.3.3.1
Search vendor "Opensuse" for product "Canna" and version " < 3.7p3-bp154.3.3.1"
-
Affected
in Opensuse
Search vendor "Opensuse"
Backports Sle
Search vendor "Opensuse" for product "Backports Sle"
15.0
Search vendor "Opensuse" for product "Backports Sle" and version "15.0"
sp4
Safe
Opensuse
Search vendor "Opensuse"
Canna
Search vendor "Opensuse" for product "Canna"
3.7p3
Search vendor "Opensuse" for product "Canna" and version "3.7p3"
-
Affected
in Opensuse
Search vendor "Opensuse"
Factory
Search vendor "Opensuse" for product "Factory"
--
Safe
Opensuse
Search vendor "Opensuse"
Canna
Search vendor "Opensuse" for product "Canna"
3.7p3
Search vendor "Opensuse" for product "Canna" and version "3.7p3"
-
Affected
in Suse
Search vendor "Suse"
Linux Enterprise
Search vendor "Suse" for product "Linux Enterprise"
12.0
Search vendor "Suse" for product "Linux Enterprise" and version "12.0"
-
Safe