vulnerability
Gentoo Linux: CVE-2019-25016: OpenDoas: Insufficient environment filtering
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:L/Au:S/C:P/I:P/A:P) | Jan 28, 2021 | Jul 8, 2021 | Mar 31, 2026 |
Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Jan 28, 2021
Added
Jul 8, 2021
Modified
Mar 31, 2026
Description
In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user to execute specific commands were not affected by this issue.
Solution
gentoo-linux-upgrade-app-admin-doas
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.