VYPR

rpm package

suse/spacewalk-proxy&distro=SUSE Manager Proxy 3.2

pkg:rpm/suse/spacewalk-proxy&distro=SUSE%20Manager%20Proxy%203.2

Vulnerabilities (3)

  • CVE-2019-10136Jul 2, 2019
    affected < 2.8.5.6-3.11.1fixed 2.8.5.6-3.11.1

    It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.

  • CVE-2019-10137Jul 2, 2019
    affected < 2.8.5.6-3.11.1fixed 2.8.5.6-3.11.1

    A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to the proxy's filesystem, or ca

  • CVE-2019-3684May 13, 2019
    affected < 2.8.5.5-3.6.2fixed 2.8.5.5-3.6.2

    SUSE Manager until version 4.0.7 and Uyuni until commit 1b426ad5ed0a7191a6fb46bb83e98ae4b99a5ade created world-readable swap files on systems that don't have a swap already configured and don't have btrfs as filesystem