First published: Fri Dec 17 2021(Updated: )
A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Longhorn | <1.1.3 | |
Linuxfoundation Longhorn | >=1.2.0<1.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36779 has a high severity rating due to the potential for unauthorized execution of binaries on the host system.
To fix CVE-2021-36779, upgrade SUSE Longhorn to version 1.1.3 or later.
CVE-2021-36779 affects SUSE Longhorn versions prior to 1.1.3 and versions between 1.2.0 and 1.2.3.
The impact of CVE-2021-36779 is that it allows any workload in the cluster to execute any binary on the host without authentication.
CVE-2021-36779 is considered a local vulnerability as it requires access to the cluster to exploit.