← Vulnerability feed

Vulnerability record · CVE-2022-31251 · published 7 September 2022

CVE-2022-31251: Opensuse factory incorrect default permissions vulnerability

Opensuse · Factory

A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prior to 22.05.2-3.3.

6.3 CVSS 3.1 Medium EPSS 0.21% · top 89.6% CWE-276 · Incorrect default permissions
6.3CVSS 3.1 base score
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prior to 22.05.2-3.3.

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugzilla.suse.com/show_bug.cgi?id=1201674 ExploitIssue TrackingThird Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1201674 ExploitIssue TrackingThird Party Advisory

Track CVE-2022-31251 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2022-31256Opensuse factory link following vulnerabilityA Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory…EPSS 0.24%7.8CVE-2021-45082Cobbler project cobbler command injection vulnerabilityAn issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Pyth…EPSS 0.50%7.8CVE-2021-25319Opensuse factory incorrect default permissions vulnerabilityA Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to es…EPSS 0.26%7.5CVE-2021-41819Ruby-lang cgi reliance on cookies without validation vulnerabilityCGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.EPSS 2.9%7.5CVE-2021-41817Ruby-lang date inefficient regular expression (redos) vulnerabilityDate.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1…EPSS 3.2%7.1CVE-2021-4166Vim out-of-bounds read vulnerabilityvim is vulnerable to Out-of-bounds ReadEPSS 1.6%5.5CVE-2021-46141Uriparser project uriparser use after free vulnerabilityAn issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.EPSS 1.1%5.5CVE-2021-46142Uriparser project uriparser use after free vulnerabilityAn issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2022-31251), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.