Vulnerability Summary: - Insufficient environment filtering in OpenDoas leading to privilege escalation. - GLSA: 202107-11 Affected Packages: - Package: - Affected Versions: =6.8.1 Severity: Normal Exploitability: Local Description: - OpenDoas does not properly filter the PATH variable from the resulting shell after escalating privileges. Impact: - A local attacker with control of a user's PATH variable could escalate privileges if that user uses OpenDoas with a poisoned PATH variable. Resolution: - Upgrade to the latest version using: References: - CVE-2019-25016