CVE-2019-18900: libzypp stores cookies world readable
: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.0 libzypp versions prior to 16.21.2-27.68.1. SUSE Linux Enterprise Server 12 libzypp versions prior to 16.21.2-2.45.1. SUSE Linux Enterprise Server 15 17.19.0-3.34.1.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-18900.
What is the severity of CVE-2019-18900?
The severity of CVE-2019-18900 is medium with a CVSS score of 3.3.
Which software versions are affected by CVE-2019-18900?
CVE-2019-18900 affects SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, and SUSE Linux Enterprise Server 15.
What is the impact of CVE-2019-18900?
CVE-2019-18900 allows local attackers to read a cookie store used by libzypp, exposing private cookies.
Are there any references for CVE-2019-18900?
Yes, you can find references for CVE-2019-18900 at the following links: [Link1], [Link2], [Link3].