A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://bugzilla.suse.com/show_bug.cgi?id=1191818 | issue tracking vendor advisory |
https://github.com/longhorn/longhorn/security/advisories/GHSA-g358-m2wp-mhhx | vendor advisory |