Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SUSE — Vulnerabilities & Security Advisories 214

Browse all 214 CVE security advisories affecting SUSE. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SUSE operates primarily as a provider of enterprise Linux distributions and cloud-native solutions, serving critical infrastructure in hybrid and multi-cloud environments. With 185 recorded CVEs, its vulnerability profile reflects the complexity of managing large-scale open-source codebases. Historically, common flaw classes include remote code execution (RCE), buffer overflows, and privilege escalation vulnerabilities, often stemming from misconfigurations or outdated dependencies within its core operating system components. Notable security characteristics involve its focus on container security and Kubernetes integration, which introduces attack surfaces related to orchestration layers. While no single catastrophic incident defines its history, the sheer volume of vulnerabilities highlights the ongoing challenge of maintaining security in widely deployed, long-term support releases. This necessitates rigorous patch management and continuous monitoring to mitigate risks associated with its extensive ecosystem of integrated services and third-party libraries.

CVE ID Title CVSS Severity Published
CVE-2023-22650 Rancher does not automatically clean up a user deleted or disabled from the configured Authentication Provider — rancher CWE-287 8.8 High 2024-10-16
CVE-2023-22649 Rancher 'Audit Log' leaks sensitive information — rancher CWE-532 8.4 High 2024-10-16
CVE-2023-22644 JWT token compromise can allow malicious actions including Remote Code Execution (RCE) — neuvector CWE-1270 7.5 - 2023-09-20
CVE-2023-32182 SUSE Linux Enterprise Desktop 后置链接漏洞 — SUSE Linux Enterprise Desktop 15 SP5 CWE-59 5.9 Medium 2023-09-19
CVE-2023-32186 RKE2 安全漏洞 — RKE2 CWE-770 7.5 High 2023-09-19
CVE-2023-32187 SUSE Rancher K3s 安全漏洞 — k3s CWE-770 7.5 High 2023-09-18
CVE-2022-43760 Rancher Labs Rancher 跨站脚本漏洞 — Rancher CWE-79 8.4 High 2023-06-01
CVE-2023-22647 Rancher Labs Rancher 安全漏洞 — Rancher CWE-267 9.9 Critical 2023-06-01
CVE-2023-22648 Rancher Labs Rancher 安全漏洞 — Rancher CWE-271 8.0 High 2023-06-01
CVE-2023-22651 Rancher 安全漏洞 — Rancher CWE-269 9.9 Critical 2023-05-04
CVE-2023-22645 kubewarden: Excessive permissions for kubewarden-controller-manager-cluster-role — kubewarden CWE-269 8.0 High 2023-04-19
CVE-2022-45155 obs-service-go_modules: arbitrary directory delete — openSUSE Factory CWE-755 5.5 Medium 2023-03-15
CVE-2022-45153 saphanabootstrap-formula: Escalation to root for arbitrary users in hana/ha_cluster.sls — SUSE Linux Enterprise Module for SAP Applications 15-SP1 CWE-276 7.0 High 2023-02-15
CVE-2022-45154 supportconfig does not remove passwords in /etc/iscsi/iscsid.conf and /etc/target/lio_setup.sh — SUSE Linux Enterprise Server 12 CWE-312 4.4 Medium 2023-02-15
CVE-2022-21953 Authenticated user can gain unauthorized shell pod and kubectl access in the local cluster — Rancher CWE-862 7.4 High 2023-02-07
CVE-2022-31249 [RANCHER] OS command injection in Rancher and Fleet — Rancher CWE-78 7.5 High 2023-02-07
CVE-2022-31254 rmt-server-pubcloud allows to escalate from user _rmt to root — SUSE Linux Enterprise Server for SAP 15 CWE-276 7.8 High 2023-02-07
CVE-2022-43755 Rancher: Non-random authentication token — Rancher CWE-331 7.1 High 2023-02-07
CVE-2022-43756 Rancher/Wrangler: Denial of service when processing Git credentials — Rancher CWE-74 5.9 Medium 2023-02-07
CVE-2022-43757 Rancher: Exposure of sensitive fields — Rancher CWE-312 9.9 Critical 2023-02-07
CVE-2022-43758 Rancher: Command injection in Git package — Rancher CWE-78 7.6 High 2023-02-07
CVE-2022-43759 Rancher: Privilege escalation via promoted roles — Rancher CWE-269 7.2 High 2023-02-07
CVE-2023-22643 libzypp-plugin-appdata: potential arbitrary code execution via shell injection due to `os.system` calls — SUSE Linux Enterprise Server for SAP 15-SP3 CWE-78 6.3 Medium 2023-02-07
CVE-2022-43754 SUMA/UYUNI reflected cross site scripting in /rhn/audit/scap/Search.do — SUSE Linux Enterprise Module for SUSE Manager Server 4.2 CWE-79 2.6 Low 2022-11-10
CVE-2022-43753 SUMA/UYUNI arbitrary file disclosure vulnerability in ScapResultDownload — SUSE Linux Enterprise Module for SUSE Manager Server 4.2 CWE-22 4.3 Medium 2022-11-10
CVE-2022-31255 SUMA/UYUNI directory path traversal vulnerability in CobblerSnipperViewAction — SUSE Linux Enterprise Module for SUSE Manager Server 4.2 CWE-22 4.3 Medium 2022-11-10
CVE-2022-31256 sendmail: mail to root privilege escalation via sm-client.pre script — openSUSE Factory CWE-59 7.7 High 2022-10-26
CVE-2022-31252 permissions: chkstat does not check for group-writable parent directories or target files in safeOpen() — SUSE Linux Enterprise Server 12-SP5 CWE-863 4.4 Medium 2022-10-06
CVE-2022-31251 slurm: %post for slurm-testsuite operates as root in user owned directory — openSUSE Factory CWE-276 6.5 Medium 2022-09-07
CVE-2022-31247 Rancher: Downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB) — Rancher CWE-285 9.1 Critical 2022-09-07

This page lists every published CVE security advisory associated with SUSE. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.