← Back

CVE-2019-18900

nvd nist
Published: Jan 24, 2020Modified: Nov 21, 2024

JSON object

Loading...
3.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.8 / Impact: 1.4
Source: NVD

Description

: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.0 libzypp versions prior to 16.21.2-27.68.1. SUSE Linux Enterprise Server 12 libzypp versions prior to 16.21.2-2.45.1. SUSE Linux Enterprise Server 15 17.19.0-3.34.1.

Affected (3)

Products: Opensuse: Libzypp
1 product
Libzypp
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 16.21.2-27.68.1
Running on/withPlatform Versions
Suse
Caas Platform
Version 3.0
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 16.21.2-2.45.1
Running on/withPlatform Versions
Suse
Suse Linux Enterprise Server
Version 12
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 17.19.0-3.34.1
Running on/withPlatform Versions
Suse
Suse Linux Enterprise Server
Version 15

References (6)

Source: meissner@suse.de
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.