A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate to root. This issue affects Tumbleweed: from ? before 2.11.29.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Sep 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensuse
Opensuse tumbleweed |
|
| Vendors & Products |
Opensuse
Opensuse tumbleweed |
Wed, 03 Sep 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | traefik: Escalation to root from traefik user via %post script | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 02 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Sep 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate to root. This issue affects Tumbleweed: from ? before 2.11.29. | |
| Weaknesses | CWE-61 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: suse
Published: 2025-09-02T11:34:32.138Z
Updated: 2025-09-03T03:55:31.087Z
Reserved: 2025-04-30T11:28:04.728Z
Link: CVE-2025-46810
Updated: 2025-09-02T13:33:29.303Z
Status : Awaiting Analysis
Published: 2025-09-02T12:15:36.250
Modified: 2025-09-02T15:55:25.420
Link: CVE-2025-46810