{ "schema_version": "1.4.0", "id": "GHSA-mfrp-422x-34qv", "modified": "2022-12-03T15:30:26Z", "published": "2022-05-24T17:26:14Z", "aliases": [ "CVE-2020-15861" ], "details": "Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-15861" }, { "type": "WEB", "url": "https://github.com/net-snmp/net-snmp/issues/145" }, { "type": "WEB", "url": "https://github.com/net-snmp/net-snmp/commit/4fd9a450444a434a993bc72f7c3486ccce41f602" }, { "type": "WEB", "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=966599" }, { "type": "WEB", "url": "https://security.gentoo.org/glsa/202008-12" }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20200904-0001" }, { "type": "WEB", "url": "https://usn.ubuntu.com/4471-1" } ], "database_specific": { "cwe_ids": [ "CWE-59" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-08-20T01:17:00Z" } }