← Vulnerability feed

Vulnerability record · CVE-2022-31256 · published 26 October 2022

CVE-2022-31256: Opensuse factory link following vulnerability

Opensuse · Factory

A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1.

7.8 CVSS 3.1 High EPSS 0.24% · top 86.7% CWE-59 · Link following
7.8CVSS 3.1 base score
0.24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE Factory allows local attackers to escalate from user mail to root. This issue affects: SUSE openSUSE Factory sendmail versions prior to 8.17.1-1.1.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugzilla.suse.com/show_bug.cgi?id=1204696 Issue TrackingVendor Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1204696 Issue TrackingVendor Advisory

Track CVE-2022-31256 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2021-45082Cobbler project cobbler command injection vulnerabilityAn issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Pyth…EPSS 0.50%7.8CVE-2021-25319Opensuse factory incorrect default permissions vulnerabilityA Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to es…EPSS 0.26%7.5CVE-2021-41819Ruby-lang cgi reliance on cookies without validation vulnerabilityCGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.EPSS 2.9%7.5CVE-2021-41817Ruby-lang date inefficient regular expression (redos) vulnerabilityDate.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1…EPSS 3.2%7.1CVE-2021-4166Vim out-of-bounds read vulnerabilityvim is vulnerable to Out-of-bounds ReadEPSS 1.6%6.3CVE-2022-31251Opensuse factory incorrect default permissions vulnerabilityA Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over th…EPSS 0.21%5.5CVE-2021-46141Uriparser project uriparser use after free vulnerabilityAn issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.EPSS 1.1%5.5CVE-2021-46142Uriparser project uriparser use after free vulnerabilityAn issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2022-31256), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.