SUSE openSUSE Factory assigns ownership of the /var/log/cobbler/ directory tree to the web-service user account, which might allow local users to gain privileges by leveraging access to this account during root filesystem operations by the Cobbler daemon.
AV:L/AC:M/Au:N/C:C/I:C/A:C
This vulnerability has a 0.34% probability of being exploited in the next 30 days, ranking higher than 25% of all scored CVEs.