Micro Focus SUSE CaaS Platform是英国Micro Focus公司的一套企业级容器管理解决方案。该产品主要用于部署、管理和扩展基于容器的应用程序及服务。libzypp是一款软件包管理器。 libzypp中存在安全漏洞。攻击者可利用该漏洞获取敏感信息。以下产品及版本受到影响:SUSE CaaS Platform 3.0 libzypp 16.21.2-27.68.1之前版本,SUSE Linux Enterprise Server 12 libzypp 16.21.2-2.45.1
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SUSE | CaaS Platform 3.0 | libzypp ~ 16.21.2-27.68.1 | - |
|
| SUSE | SUSE Linux Enterprise Server 12 | libzypp ~ 16.21.2-2.45.1 | - |
|
| SUSE | SUSE Linux Enterprise Server 15 | libzypp 17.19.0-3.34.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-3692 | 7.7 HIGH | Local privilege escalation from user news to root in the packaging of inn |
| CVE-2019-3693 | 7.7 HIGH | Local privilege escalation from user wwwrun to root in the packaging of mailman |
| CVE-2019-3687 | 4.0 MEDIUM | "easy" permission profile allows everyone execute dumpcap and read all network traffic |
No comments yet