suse · CVE-2019-18900

Quick triage

Priority: medium Published: 2021-05-30 14:33:05 UTC Updated: 2026-03-05 06:04:56 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2019-18900 severity moderate: SUSE including 421 source package names (0.1.0:libsolv-tools-0.7.10-3.13.4, 0.1.0:libzypp-17.19.0-3.14.5, …), 612 product×package rows across 132 product lines (Container caasp/v4/389-ds, Container caasp/v4/busybox, … (132 product lines)): Fixed 343, Known Affected 157, Known Not Affected 112.

Description:

: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.0 libzypp versions prior to 16.21.2-27.68.1. SUSE Linux Enterprise Server 12 libzypp versions prior to 16.21.2-2.45.1. SUSE Linux Enterprise Server 15 17.19.0-3.34.1.

cvelogic Threat Intelligence