vulnerability

SUSE: CVE-2019-18897: SUSE Linux Security Advisory

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Mar 2, 2020
Added
Mar 11, 2020
Modified
Feb 4, 2022

Description

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version 2019.2.0-46.83.1 and prior versions. SUSE Linux Enterprise Server 15 salt-master version 2019.2.0-6.21.1 and prior versions. openSUSE Factory salt-master version 2019.2.2-3.1 and prior versions.

Solutions

suse-upgrade-python-singledispatchsuse-upgrade-python2-saltsuse-upgrade-python3-saltsuse-upgrade-saltsuse-upgrade-salt-apisuse-upgrade-salt-bash-completionsuse-upgrade-salt-cloudsuse-upgrade-salt-docsuse-upgrade-salt-fish-completionsuse-upgrade-salt-mastersuse-upgrade-salt-minionsuse-upgrade-salt-proxysuse-upgrade-salt-sshsuse-upgrade-salt-standalone-formulas-configurationsuse-upgrade-salt-syndicsuse-upgrade-salt-zsh-completion

References

    Title
    NEW

    Explore Exposure Command

    Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.