rpm package
opensuse/tcmu-runner&distro=openSUSE Leap 15.2
pkg:rpm/opensuse/tcmu-runner&distro=openSUSE%20Leap%2015.2
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-3139 | Hig | 8.1 | < 1.5.2-lp152.2.3.1 | 1.5.2-lp152.2.3.1 | Jan 13, 2021 | In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur |
- affected < 1.5.2-lp152.2.3.1fixed 1.5.2-lp152.2.3.1
In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur