Malte Kraus

#1704de 53,638
134.1CVSS total
Vulnerabilidades · 17
Baixa
1
Média
3
Alta
8
Crítica
5
PT-2020-19929
9.3
2020-09-16
Google · Google-Gson · CVE-2020-8028
**Nome do software vulnerável e versões afetadas** SUSE Linux Enterprise Module para SUSE Manager Server 4.1 SUSE Manager Proxy 4.0, versões anteriores à 4.0.9-0.16.38.1 SUSE Manager Retail Branch Server 4.0, versões anteriores à 4.0.9-0.16.38.1 SUSE Manager Server 3.2 SUSE Manager Server 4.0 versões anteriores à 4.0.9-3.54.1 google-gson versões anteriores à 2.8.5-3.4.3 httpcomponents-client versões anteriores à 4.5.6-3.4.2 **Descrição** Uma vulnerabilidade na configuração do salt permite que usuários locais obtenham privilégios de root em todos os sistemas gerenciados pelo SUSE Manager. No próprio nó de gerenciamento, o código pode ser executado como usuário salt, permitindo potencialmente a escalada para root nesse local. **Recomendações** Para o SUSE Linux Enterprise Module para SUSE Manager Server 4.1, atualize para uma versão que inclua a correção para este problema. Para o SUSE Manager Proxy 4.0, atualize para a versão 4.0.9-0.16.38.1 ou posterior. Para o SUSE Manager Retail Branch Server 4.0, atualize para a versão 4.0.9-0.16.38.1 ou posterior. Para o SUSE Manager Server 3.2, atualize o salt-netapi-client para a versão 0.16.0-4.14.1 ou posterior. Para o SUSE Manager Server 4.0, atualize para a versão 4.0.9-3.54.1 ou posterior. Para o google-gson, atualize para a versão 2.8.5-3.4.3 ou posterior. Para o httpcomponents-client, atualize para a versão 4.5.6-3.4.2 ou posterior.
PT-2019-5543
10
2019-01-21
Suse · Opensuse Leap 15.1 · CVE-2019-3681
**Name of the Vulnerable Software and Affected Versions** SUSE Linux Enterprise Module for Development Tools 15 osc versions prior to 0.169.1-3.20.1 SUSE Linux Enterprise Software Development Kit 12-SP5 osc versions prior to 0.162.1-15.9.1 SUSE Linux Enterprise Software Development Kit 12-SP4 osc versions prior to 0.162.1-15.9.1 openSUSE Leap 15.1 osc versions prior to 0.169.1-lp151.2.15.1 openSUSE Factory osc versions prior to 0.169.0 **Description** A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE Linux Enterprise Software Development Kit 12-SP4, openSUSE Leap 15.1, and openSUSE Factory allowed remote attackers that can change downloaded packages to overwrite arbitrary files. This issue is related to incorrect external control of file name or path, which may allow a remote attacker to elevate their privileges. **Recommendations** For SUSE Linux Enterprise Module for Development Tools 15 osc versions prior to 0.169.1-3.20.1, update to version 0.169.1-3.20.1 or later. For SUSE Linux Enterprise Software Development Kit 12-SP5 osc versions prior to 0.162.1-15.9.1, update to version 0.162.1-15.9.1 or later. For SUSE Linux Enterprise Software Development Kit 12-SP4 osc versions prior to 0.162.1-15.9.1, update to version 0.162.1-15.9.1 or later. For openSUSE Leap 15.1 osc versions prior to 0.169.1-lp151.2.15.1, update to version 0.169.1-lp151.2.15.1 or later. For openSUSE Factory osc versions prior to 0.169.0, update to version 0.169.0 or later.