Vulnerabilities (CVE)

Filtered by vendor Linuxfoundation Subscribe
Filtered by product Longhorn
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-36779 1 Linuxfoundation 1 Longhorn 2021-12-30 8.3 HIGH 9.6 CRITICAL
A Improper Access Control vulnerability inf SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3.
CVE-2021-36780 1 Linuxfoundation 1 Longhorn 2021-12-30 4.8 MEDIUM 8.1 HIGH
A Improper Access Control vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica instance granting it the ability to read and write data to and from a replica that they should not have access to. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3v.