VYPR

skuba

by SUSE S.A.

CVEs (2)

  • CVE-2020-8030Feb 11, 2021
    risk 0.00cvss epss 0.00

    A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to leak the bootstrapToken or modify the configuration file before it is processed, leading to arbitrary modifications of the machine/cluster.

  • CVE-2020-8029Feb 11, 2021
    risk 0.00cvss epss 0.00

    A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to gain access to the kublet key. This issue affects: SUSE CaaS Platform 4.5 skuba versions prior to https://github.com/SUSE/skuba/pull/1416.