Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
Vulnerability Description
An attacker with network-level access between the SUSE Virtualization
and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it
to bypass TLS as a security control.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Vulnerability Type
证书验证不恰当
Vulnerability Title
SUSE Harvester 加密问题漏洞
Vulnerability Description
SUSE Harvester是德国SUSE公司的一个云基础设施平台。 SUSE Harvester 1.8.0之前版本存在加密问题漏洞,该漏洞源于TLS握手过程中的缺陷,可能导致具有网络级访问权限的攻击者绕过TLS安全控制。
CVSS Information
N/A
Vulnerability Type
N/A