suse · CVE-2018-15869

Quick triage

Priority: high Published: 2021-05-30 14:16:06 UTC Updated: 2026-04-17 15:18:50 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-15869 severity important: SUSE including 302 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 315 product×package rows across 28 product lines (HPE Helion OpenStack 8, Image SLES12-SP5-EC2-BYOS, … (28 product lines)): Known Affected 231, Fixed 82, Known Not Affected 2.

Description:

An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurated public community AMI catalog.

cvelogic Threat Intelligence