Описание
A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica instance granting it the ability to read and write data to and from a replica that they should not have access to. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3v.
Ссылки
- Issue TrackingVendor Advisory
- Third Party Advisory
- Issue TrackingVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.3 (исключая)Версия от 1.2.0 (включая) до 1.2.3 (исключая)
Одно из
cpe:2.3:a:linuxfoundation:longhorn:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:longhorn:*:*:*:*:*:*:*:*
EPSS
Процентиль: 18%
0.00055
Низкий
8.1 High
CVSS3
4.8 Medium
CVSS2
Дефекты
CWE-306
CWE-306
EPSS
Процентиль: 18%
0.00055
Низкий
8.1 High
CVSS3
4.8 Medium
CVSS2
Дефекты
CWE-306
CWE-306