A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate to root. This issue affects Tumbleweed: from ? before 2.11.29.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Sep 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Opensuse
Opensuse tumbleweed |
|
Vendors & Products |
Opensuse
Opensuse tumbleweed |
Wed, 03 Sep 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | traefik: Escalation to root from traefik user via %post script | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Tue, 02 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 02 Sep 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate to root. This issue affects Tumbleweed: from ? before 2.11.29. | |
Weaknesses | CWE-61 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: suse
Published: 2025-09-02T11:34:32.138Z
Updated: 2025-09-03T03:55:31.087Z
Reserved: 2025-04-30T11:28:04.728Z
Link: CVE-2025-46810

Updated: 2025-09-02T13:33:29.303Z

Status : Awaiting Analysis
Published: 2025-09-02T12:15:36.250
Modified: 2025-09-02T15:55:25.420
Link: CVE-2025-46810
