RSS   Vulnerabilities for 'Caas platform'   RSS

2021-02-11
 
CVE-2020-8030

CWE-377
 

 
A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to leak the bootstrapToken or modify the configuration file before it is processed, leading to arbitrary modifications of the machine/cluster.

 
 
CVE-2020-8029

CWE-732
 

 
A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to gain access to the kublet key. This issue affects: SUSE CaaS Platform 4.5 skuba versions prior to https://github.com/SUSE/skuba/pull/1416.

 
2020-01-17
 
CVE-2019-3682

CWE-668
 

 
The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node.

 
2018-08-10
 
CVE-2018-6556

CWE-417
 

 
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.

 

 >>> Vendor: SUSE 74 Products
Suse linux
Suse linux imap server
Suse linux openexchange server
Office server
Suse email server
Suse linux admin-cd for firewall
Suse linux connectivity server
Suse linux database server
Suse linux firewall cd
Suse linux office server
Suse office server
Suse linux firewall
Suse linux firewall live-cd
Suse iptables
Suse cvsup
Suse linux school server
Suse linux standard server
Suse sled beagle
Suse open enterprise server
Linux enterprise desktop
Opensuse
Open suse
Yast2-backup
VPNC
Webyast
Studio onsite
Studio extension for system z
KIWI
Suse linux enterprise desktop
Suse linux enterprise software development kit
GCAB
Opensuse osc
Linux enterprise server
Linux enterprise debuginfo
Suse linux enterprise server
Manager
Linux enterprise software development kit
Linux enterprise workstation extension
Openstack cloud
Yast2
Manager proxy
Openstack
Linux enterprise
Suse linux enterprise live patching
Suse linux enterprise module for public cloud
Suse linux enterprise workstation extension
Linux enterprise real time extension
Opensuse leap
Suse linux enterprise real time extension
Suse linux workstation extension
Linux enterprise server for sap
Linux enterprise server for raspberry pi
Linux enterprise high availability
Linux enterprise module for web scripting
Linux enterprise for sap
Portus
Linux enterprise point of sale
Susefirewall2
Open build service
Linux enterprise module for public cloud
Subscription management tool
Shadow
Suse enterprise storage
Suse openstack cloud
Backports
Package hub
Caas platform
Repository mirroring tool
Openqa
Susestudio-ui-server
Yast2-security
Keystone json assignment
Openstack cloud crowbar
Linux enterprise high performance computing


Copyright 2021, cxsecurity.com

 

Back to Top