Impact
The vulnerability allows an OS command injection through the shadowLastChange and shadowExpire LDAP attributes. When the "Password Settings" tab is displayed, the values are read without numeric validation and interpolated into shell commands executed via Ruby backticks. This flaw falls under CWE-78 and can lead an administrator to execute arbitrary commands with root privileges.
Affected Systems
The flaw affects SUSE yast2-users versions through 5.0.8 when the system is configured to manage users through an external LDAP directory. Management of user accounts via the yast2 users interface is required, but no domain join or trust configuration is necessary.
Risk and Exploitability
With a CVSS score of 8.6 the vulnerability is considered high severity. The EPSS score is not available and the issue is not listed in CISA KEV, suggesting no widespread exploitation yet. The attack vector is local: an administrator who can launch yast2-users must trigger the vulnerable code by viewing or editing a user’s "Password Settings" tab. Successful exploitation results in root command execution, giving full control over the system.
OpenCVE Enrichment