cbcvebase.

Suse Caas Platform vulnerabilities

6 known vulnerabilities affecting suse/caas_platform.

Total CVEs
6
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH3MEDIUM2LOW1

Vulnerabilities

Page 1 of 1
CVE-2026-31431P1HIGHCVSS 7.8KEVPoCv4.02026-04-22
CVE-2026-31431 [HIGH] CWE-669 CVE-2026-31431: In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the compl
nvd
CVE-2022-27239P3HIGHCVSS 7.8v4.02022-04-27
CVE-2022-27239 [HIGH] CWE-787 CVE-2022-27239: In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-li In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
nvd
CVE-2019-3682P3HIGHCVSS 7.8v3.02020-01-17
CVE-2019-3682 [HIGH] CWE-668 CVE-2019-3682: The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an ins The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node.
nvd
CVE-2020-8030P4MEDIUMCVSS 4.4v4.52021-02-11
CVE-2020-8030 [MEDIUM] CWE-377 CVE-2020-8030: A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to leak the bootstrapToken or modify the configuration file before it is processed, leading to arbitrary modifications of the machine/cluster.
nvd
CVE-2020-8029P4MEDIUMCVSS 4.0v4.52021-02-11
CVE-2020-8029 [MEDIUM] CWE-732 CVE-2020-8029: A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to gain access to the kublet key. This issue affects: SUSE CaaS Platform 4.5 skuba versions prior to https://github.com/SUSE/skuba/pull/1416.
nvd
CVE-2018-6556P4LOWCVSS 3.3v1.0v2.02018-08-10
CVE-2018-6556 [LOW] CWE-417 CVE-2018-6556: lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). A
nvd
Suse Caas Platform vulnerabilities | cvebase