CVE-2020-8030: skuba: Insecure /tmp usage when joining node to cluster
A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to leak the bootstrapToken or modify the configuration file before it is processed, leading to arbitrary modifications of the machine/cluster.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-8030.
What is the title of this vulnerability?
The title of this vulnerability is 'A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to...'
What is the affected software for this vulnerability?
The affected software for this vulnerability is SUSE CaaS Platform 4.5.
What is the severity level of this vulnerability?
The severity level of this vulnerability is medium (4.4).
How can this vulnerability be exploited?
This vulnerability can be exploited by local attackers to leak the bootstrapToken or modify the configuration file before it is processed, leading to arbitrary modifications of the machine/cluster.