Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 2 |
CVE-ID | CVE-2022-1996 CVE-2022-36055 |
CWE-ID | CWE-942 CWE-400 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
SUSE Linux Enterprise Module for Containers Operating systems & Components / Operating system SUSE Manager Retail Branch Server Operating systems & Components / Operating system SUSE Linux Enterprise Storage Operating systems & Components / Operating system SUSE Manager Server Operating systems & Components / Operating system SUSE Manager Proxy Operating systems & Components / Operating system openSUSE Leap Operating systems & Components / Operating system SUSE Linux Enterprise Server for SAP Applications Operating systems & Components / Operating system SUSE Linux Enterprise Server Operating systems & Components / Operating system SUSE Linux Enterprise High Performance Computing Operating systems & Components / Operating system SUSE Linux Enterprise Module for Packagehub Subpackages Operating systems & Components / Operating system package or component helm-zsh-completion Operating systems & Components / Operating system package or component helm-fish-completion Operating systems & Components / Operating system package or component helm-bash-completion Operating systems & Components / Operating system package or component helm-debuginfo Operating systems & Components / Operating system package or component helm Operating systems & Components / Operating system package or component |
Vendor | SUSE |
Security Bulletin
This security bulletin contains information about 2 vulnerabilities.
EUVDB-ID: #VU66447
Risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-1996
CWE-ID:
CWE-942 - Overly Permissive Cross-domain Whitelist
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass the CORS protection mechanism.
The vulnerability exists due to incorrect processing of the "Origin" HTTP header that is supplied within HTTP request. A remote attacker can supply arbitrary value via the "Origin" HTTP header, bypass implemented CORS protection mechanism and perform cross-site scripting attacks against the vulnerable application.
MitigationUpdate the affected package helm to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Module for Containers: 15-SP3 - 15-SP4
SUSE Manager Retail Branch Server: 4.2 - 4.3
SUSE Linux Enterprise Storage: 7.1
SUSE Linux Enterprise Module for Packagehub Subpackages: 15-SP3 - 15-SP4
SUSE Manager Server: 4.2 - 4.3
SUSE Manager Proxy: 4.2 - 4.3
openSUSE Leap: 15.3 - 15.4
SUSE Linux Enterprise Server for SAP Applications: 15-SP3 - 15-SP4
SUSE Linux Enterprise Server: 15-SP3 - 15-SP4
SUSE Linux Enterprise High Performance Computing: 15-SP3 - 15-SP4
helm-zsh-completion: before 3.9.4-150000.1.10.3
helm-fish-completion: before 3.9.4-150000.1.10.3
helm-bash-completion: before 3.9.4-150000.1.10.3
helm-debuginfo: before 3.9.4-150000.1.10.3
helm: before 3.9.4-150000.1.10.3
CPE2.3https://www.suse.com/support/update/announcement/2022/suse-su-20223666-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU67945
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-36055
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect resource management within the strvals package, responsible for converting strings into Go structures. A remote attacker can pass specially crafted input to the application and consume all available memory on the system.
MitigationUpdate the affected package helm to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Module for Containers: 15-SP3 - 15-SP4
SUSE Manager Retail Branch Server: 4.2 - 4.3
SUSE Linux Enterprise Storage: 7.1
SUSE Linux Enterprise Module for Packagehub Subpackages: 15-SP3 - 15-SP4
SUSE Manager Server: 4.2 - 4.3
SUSE Manager Proxy: 4.2 - 4.3
openSUSE Leap: 15.3 - 15.4
SUSE Linux Enterprise Server for SAP Applications: 15-SP3 - 15-SP4
SUSE Linux Enterprise Server: 15-SP3 - 15-SP4
SUSE Linux Enterprise High Performance Computing: 15-SP3 - 15-SP4
helm-zsh-completion: before 3.9.4-150000.1.10.3
helm-fish-completion: before 3.9.4-150000.1.10.3
helm-bash-completion: before 3.9.4-150000.1.10.3
helm-debuginfo: before 3.9.4-150000.1.10.3
helm: before 3.9.4-150000.1.10.3
CPE2.3https://www.suse.com/support/update/announcement/2022/suse-su-20223666-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.