Vulnerabilities > Opensuse > Leap Micro > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-10-06 CVE-2022-31252 Incorrect Authorization vulnerability in multiple products
A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE Leap Micro 5.2 did not consider group writable path components, allowing local attackers with access to a group what can write to a location included in the path to a privileged binary to influence path resolution.
local
low complexity
suse opensuse CWE-863
4.4