rpm package
suse/uyuni-common-libs&distro=SUSE Manager Proxy Module 4.3
pkg:rpm/suse/uyuni-common-libs&distro=SUSE%20Manager%20Proxy%20Module%204.3
Vulnerabilities (8)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-49503 | Low | 3.5 | < 4.3.11-150400.3.21.6 | 4.3.11-150400.3.21.6 | Nov 28, 2024 | A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SUSE manager allows attackers to execute Javascript code in the organization credentials sub page. This issue affects Container suse/manager/5.0/x86_64/server:5.0.2.7.8. | |
| CVE-2024-49502 | Low | 3.5 | < 4.3.11-150400.3.21.6 | 4.3.11-150400.3.21.6 | Nov 28, 2024 | A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows attackers to attack users by providing specially crafted URLs to click. This issue affects Containe | |
| CVE-2024-47533 | Cri | 9.8 | < 4.3.11-150400.3.21.6 | 4.3.11-150400.3.21.6 | Nov 18, 2024 | Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyon | |
| CVE-2023-51775 | — | < 4.3.10-150400.3.18.4 | 4.3.10-150400.3.18.4 | Dec 25, 2023 | The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value. | ||
| CVE-2023-22644 | — | < 4.3.8-150400.3.12.5 | 4.3.8-150400.3.12.5 | Sep 20, 2023 | A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE. | ||
| CVE-2023-29409 | — | < 4.3.9-150400.3.15.13 | 4.3.9-150400.3.15.13 | Aug 2, 2023 | Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are curr | ||
| CVE-2021-41411 | — | < 4.3.6-150400.3.6.4 | 4.3.6-150400.3.6.4 | Jun 16, 2022 | drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability. | ||
| CVE-2022-0860 | — | < 4.3.6-150400.3.6.4 | 4.3.6-150400.3.6.4 | Mar 11, 2022 | Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2. |
- affected < 4.3.11-150400.3.21.6fixed 4.3.11-150400.3.21.6
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SUSE manager allows attackers to execute Javascript code in the organization credentials sub page. This issue affects Container suse/manager/5.0/x86_64/server:5.0.2.7.8.
- affected < 4.3.11-150400.3.21.6fixed 4.3.11-150400.3.21.6
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows attackers to attack users by providing specially crafted URLs to click. This issue affects Containe
- affected < 4.3.11-150400.3.21.6fixed 4.3.11-150400.3.21.6
Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyon
- CVE-2023-51775Dec 25, 2023affected < 4.3.10-150400.3.18.4fixed 4.3.10-150400.3.18.4
The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
- CVE-2023-22644Sep 20, 2023affected < 4.3.8-150400.3.12.5fixed 4.3.8-150400.3.12.5
A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.
- CVE-2023-29409Aug 2, 2023affected < 4.3.9-150400.3.15.13fixed 4.3.9-150400.3.15.13
Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are curr
- CVE-2021-41411Jun 16, 2022affected < 4.3.6-150400.3.6.4fixed 4.3.6-150400.3.6.4
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
- CVE-2022-0860Mar 11, 2022affected < 4.3.6-150400.3.6.4fixed 4.3.6-150400.3.6.4
Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.