Skip to main content

Vendor archive

opendoas_project CVEs

Beta · best-effort

2 CVEs tagged to vendor opendoas_project0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2023-28339

Published Mar 14, 2023

OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI is unavailable in OpenBSD 6.0…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-25016

Published Jan 28, 2021

In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1