{"api_version":"1","generated_at":"2026-07-23T11:01:05+00:00","cve":"CVE-2019-25016","urls":{"html":"https://cve.report/CVE-2019-25016","api":"https://cve.report/api/cve/CVE-2019-25016.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-25016","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-25016"},"summary":{"title":"CVE-2019-25016","description":"In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user to execute specific commands were not affected by this issue.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-01-28 20:15:00","updated_at":"2022-04-26 16:14:00"},"problem_types":["CWE-459","CWE-909"],"metrics":[],"references":[{"url":"https://github.com/Duncaen/OpenDoas/commit/01c658f8c45cb92a343be5f32aa6da70b2032168","name":"https://github.com/Duncaen/OpenDoas/commit/01c658f8c45cb92a343be5f32aa6da70b2032168","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"redo the environment inheritance to not inherit. it was intended to m… · Duncaen/OpenDoas@01c658f · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/202107-11","name":"GLSA-202107-11","refsource":"GENTOO","tags":[],"title":"OpenDoas: Insufficient environment filtering (GLSA 202107-11) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/Duncaen/OpenDoas/issues/45","name":"https://github.com/Duncaen/OpenDoas/issues/45","refsource":"MISC","tags":["Exploit","Issue Tracking","Third Party Advisory"],"title":"OpenDoas keeps current PATH variable  · Issue #45 · Duncaen/OpenDoas · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/Duncaen/OpenDoas/releases/tag/v6.8.1","name":"https://github.com/Duncaen/OpenDoas/releases/tag/v6.8.1","refsource":"MISC","tags":["Release Notes","Third Party Advisory"],"title":"Release v6.8.1: - This release fixes one major issue that has been assigned CVE-2019-… · Duncaen/OpenDoas · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/Duncaen/OpenDoas/commit/d5acd52e2a15c36a8e06f9103d35622933aa422d","name":"https://github.com/Duncaen/OpenDoas/commit/d5acd52e2a15c36a8e06f9103d35622933aa422d","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"correctly reset path for rules without specific command · Duncaen/OpenDoas@d5acd52 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-25016","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-25016","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"25016","vulnerable":"1","versionEndIncluding":"6.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opendoas_project","cpe5":"opendoas","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-25016","qid":"500161","title":"Alpine Linux Security Update for doas"},{"cve":"CVE-2019-25016","qid":"501397","title":"Alpine Linux Security Update for doas"},{"cve":"CVE-2019-25016","qid":"503894","title":"Alpine Linux Security Update for doas"},{"cve":"CVE-2019-25016","qid":"710065","title":"Gentoo Linux OpenDoas Insufficient environment filtering (GLSA 202107-11)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-25016","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user to execute specific commands were not affected by this issue."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/Duncaen/OpenDoas/commit/01c658f8c45cb92a343be5f32aa6da70b2032168","refsource":"MISC","name":"https://github.com/Duncaen/OpenDoas/commit/01c658f8c45cb92a343be5f32aa6da70b2032168"},{"url":"https://github.com/Duncaen/OpenDoas/issues/45","refsource":"MISC","name":"https://github.com/Duncaen/OpenDoas/issues/45"},{"refsource":"MISC","name":"https://github.com/Duncaen/OpenDoas/releases/tag/v6.8.1","url":"https://github.com/Duncaen/OpenDoas/releases/tag/v6.8.1"},{"refsource":"MISC","name":"https://github.com/Duncaen/OpenDoas/commit/d5acd52e2a15c36a8e06f9103d35622933aa422d","url":"https://github.com/Duncaen/OpenDoas/commit/d5acd52e2a15c36a8e06f9103d35622933aa422d"},{"refsource":"GENTOO","name":"GLSA-202107-11","url":"https://security.gentoo.org/glsa/202107-11"}]}},"nvd":{"publishedDate":"2021-01-28 20:15:00","lastModifiedDate":"2022-04-26 16:14:00","problem_types":["CWE-459","CWE-909"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:opendoas_project:opendoas:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndIncluding":"6.8","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"25016","Ordinal":"201304","Title":"CVE-2019-25016","CVE":"CVE-2019-25016","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"25016","Ordinal":"1","NoteData":"In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user to execute specific commands were not affected by this issue.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"25016","Ordinal":"2","NoteData":"2021-01-28","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"25016","Ordinal":"3","NoteData":"2021-07-07","Type":"Other","Title":"Modified"}]}}}