CyberSec.Space Logo
Back to CVE Browser

CVE-2021-40084

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0560%
EPSS Percentile22.14th
PublishedAug 25, 2021
Last ModifiedNov 21, 2024

Vulnerability Description

opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that.

Affected Platforms (CPE)

πŸ“¦
Artixlinux

Opensysusers

<= 0.6

References & Advisories

Related Vulnerabilities