Suse Caas Platform 4.5 vulnerabilities
2 known vulnerabilities affecting suse/suse_caas_platform_4.5.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2020-8029MEDIUMCVSS 4.0≥ skuba, < https://github.com/SUSE/skuba/pull/14162021-02-11
CVE-2020-8029 [LOW] CWE-732 CVE-2020-8029: A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform
A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to gain access to the kublet key. This issue affects: SUSE CaaS Platform 4.5 skuba versions prior to https://github.com/SUSE/skuba/pull/1416.
cvelistv5nvd
CVE-2020-8030MEDIUMCVSS 4.4≥ suba, < 2.1.72021-02-11
CVE-2020-8030 [LOW] CWE-377 CVE-2020-8030: A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to
A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to leak the bootstrapToken or modify the configuration file before it is processed, leading to arbitrary modifications of the machine/cluster.
cvelistv5nvd