{"api_version":"1","generated_at":"2026-07-23T13:23:33+00:00","cve":"CVE-2021-36779","urls":{"html":"https://cve.report/CVE-2021-36779","api":"https://cve.report/api/cve/CVE-2021-36779.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-36779","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-36779"},"summary":{"title":"CVE-2021-36779","description":"A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3.","state":"PUBLIC","assigner":"security@suse.com","published_at":"2021-12-17 09:15:00","updated_at":"2023-02-10 02:31:00"},"problem_types":["CWE-306"],"metrics":[],"references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1191818","name":"https://bugzilla.suse.com/show_bug.cgi?id=1191818","refsource":"CONFIRM","tags":[],"title":"Bug 1191818 – VUL-0: CVE-2021-36779: Host operations allowed in privileged Longhorn managed pods","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/longhorn/longhorn/security/advisories/GHSA-g358-m2wp-mhhx","name":"https://github.com/longhorn/longhorn/security/advisories/GHSA-g358-m2wp-mhhx","refsource":"CONFIRM","tags":[],"title":"Host operations allowed in privileged Longhorn managed pods · Advisory · longhorn/longhorn · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-36779","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-36779","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Dagan Henderson and Will Kline","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"36779","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"linuxfoundation","cpe5":"longhorn","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@suse.com","DATE_PUBLIC":"2021-12-17T00:00:00.000Z","ID":"CVE-2021-36779","STATE":"PUBLIC","TITLE":"Host operations allowed in privileged Longhorn managed pods"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Longhorn","version":{"version_data":[{"version_affected":"<","version_name":"longhorn","version_value":"1.1.3"}]}},{"product_name":"Longhorn","version":{"version_data":[{"version_affected":"<","version_name":"longhorn","version_value":"1.2.3"}]}}]},"vendor_name":"SUSE"}]}},"credit":[{"lang":"eng","value":"Dagan Henderson and Will Kline"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":9.6,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-306: Missing Authentication for Critical Function"}]}]},"references":{"reference_data":[{"name":"https://bugzilla.suse.com/show_bug.cgi?id=1191818","refsource":"CONFIRM","url":"https://bugzilla.suse.com/show_bug.cgi?id=1191818"},{"name":"https://github.com/longhorn/longhorn/security/advisories/GHSA-g358-m2wp-mhhx","refsource":"CONFIRM","url":"https://github.com/longhorn/longhorn/security/advisories/GHSA-g358-m2wp-mhhx"}]},"source":{"advisory":"https://bugzilla.suse.com/show_bug.cgi?id=1191818","defect":["1191818"],"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2021-12-17 09:15:00","lastModifiedDate":"2023-02-10 02:31:00","problem_types":["CWE-306"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.6,"baseSeverity":"CRITICAL"},"exploitabilityScore":2.8,"impactScore":6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:A/AC:L/Au:N/C:C/I:C/A:C","accessVector":"ADJACENT_NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":8.3},"severity":"HIGH","exploitabilityScore":6.5,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:linuxfoundation:longhorn:*:*:*:*:*:*:*:*","versionEndExcluding":"1.1.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:linuxfoundation:longhorn:*:*:*:*:*:*:*:*","versionStartIncluding":"1.2.0","versionEndExcluding":"1.2.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"36779","Ordinal":"212344","Title":"CVE-2021-36779","CVE":"CVE-2021-36779","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"36779","Ordinal":"1","NoteData":"A Improper Access Control vulnerability inf SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"36779","Ordinal":"2","NoteData":"2021-12-17","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"36779","Ordinal":"3","NoteData":"2021-12-17","Type":"Other","Title":"Modified"}]}}}