A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3.
                
            References
                    | Link | Resource | 
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1191818 | Issue Tracking Vendor Advisory | 
| https://github.com/longhorn/longhorn/security/advisories/GHSA-g358-m2wp-mhhx | Vendor Advisory | 
| https://bugzilla.suse.com/show_bug.cgi?id=1191818 | Issue Tracking Vendor Advisory | 
| https://github.com/longhorn/longhorn/security/advisories/GHSA-g358-m2wp-mhhx | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2021-12-17 09:15
Updated : 2024-11-21 06:14
NVD link : CVE-2021-36779
Mitre link : CVE-2021-36779
CVE.ORG link : CVE-2021-36779
JSON object : View
Products Affected
                linuxfoundation
- longhorn
CWE
                
                    
                        
                        CWE-306
                        
            Missing Authentication for Critical Function
