VYPR

Uyuni

by Uyuni Project

Source repositories

CVEs (3)

  • CVE-2024-22037MedNov 28, 2024
    risk 0.36cvss 5.5epss 0.00

    The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment is still exposed by systemd to non-privileged users.

  • CVE-2021-40348Nov 1, 2021
    risk 0.00cvss epss 0.02

    Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename used to append Spacewalk-specific key-value pair. The script is intended to be run by the tomcat user account with Sudo, according to…

  • CVE-2019-3684May 13, 2019
    risk 0.00cvss epss 0.01

    SUSE Manager until version 4.0.7 and Uyuni until commit 1b426ad5ed0a7191a6fb46bb83e98ae4b99a5ade created world-readable swap files on systems that don't have a swap already configured and don't have btrfs as filesystem