Upstream information
Description
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.SUSE information
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having important severity.
National Vulnerability Database | |
---|---|
Base Score | 8.8 |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | None |
User Interaction | Required |
Scope | Unchanged |
Confidentiality Impact | High |
Integrity Impact | High |
Availability Impact | High |
CVSSv3 Version | 3.1 |
SUSE Security Advisories:
- SUSE-SU-2023:2320-1, published Tue May 30 16:30:29 UTC 2023
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production Image SLES15-SP2-SAP-Azure-LI-BYOS-Production Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production Image SLES15-SP3-SAP-Azure-LI-BYOS-Production Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production Image SLES15-SP4-SAP-Azure-LI-BYOS Image SLES15-SP4-SAP-Azure-LI-BYOS-Production Image SLES15-SP4-SAP-Azure-VLI-BYOS Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production Image SLES15-SP5-SAP-Azure-LI-BYOS Image SLES15-SP5-SAP-Azure-LI-BYOS-Production Image SLES15-SP5-SAP-Azure-VLI-BYOS Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production |
| |
SUSE Linux Enterprise Desktop 15 SP4 SUSE Linux Enterprise High Performance Computing 15 SP4 SUSE Linux Enterprise Server 15 SP4 SUSE Linux Enterprise Server for SAP Applications 15 SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 |
| Patchnames: SUSE-SLE-Module-Basesystem-15-SP4-2023-2320 SUSE-SLE-Module-Desktop-Applications-15-SP4-2023-2320 |
SUSE Linux Enterprise Desktop 15 SP5 SUSE Linux Enterprise High Performance Computing 15 SP5 SUSE Linux Enterprise Server 15 SP5 SUSE Linux Enterprise Server for SAP Applications 15 SP5 |
| Patchnames: SUSE-SLE-Module-Basesystem-15-SP5-2023-2320 SUSE-SLE-Module-Desktop-Applications-15-SP5-2023-2320 |
SUSE Linux Enterprise Module for Basesystem 15 SP4 |
| Patchnames: SUSE-SLE-Module-Basesystem-15-SP4-2023-2320 |
SUSE Linux Enterprise Module for Basesystem 15 SP5 |
| Patchnames: SUSE-SLE-Module-Basesystem-15-SP5-2023-2320 |
SUSE Linux Enterprise Module for Desktop Applications 15 SP4 |
| Patchnames: SUSE-SLE-Module-Desktop-Applications-15-SP4-2023-2320 |
SUSE Linux Enterprise Module for Desktop Applications 15 SP5 |
| Patchnames: SUSE-SLE-Module-Desktop-Applications-15-SP5-2023-2320 |
SUSE Linux Enterprise Real Time 15 SP3 |
| Patchnames: SUSE-SLE-Product-RT-15-SP3-2023-2320 |
openSUSE Leap 15.4 |
| Patchnames: openSUSE-SLE-15.4-2023-2320 |
openSUSE Leap 15.5 |
| Patchnames: openSUSE-SLE-15.5-2023-2320 |
SUSE Timeline for this CVE
CVE page created: Wed May 24 12:00:05 2023CVE page last modified: Mon Aug 28 14:56:11 2023