CVE-2021-36779
Summary
| CVE | CVE-2021-36779 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-17 09:15:00 UTC |
| Updated | 2023-02-10 02:31:00 UTC |
| Description | A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Linuxfoundation | Longhorn | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 1191818 – VUL-0: CVE-2021-36779: Host operations allowed in privileged Longhorn managed pods | CONFIRM | bugzilla.suse.com | |
| Host operations allowed in privileged Longhorn managed pods · Advisory · longhorn/longhorn · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Dagan Henderson and Will Kline
There are currently no legacy QID mappings associated with this CVE.