Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 6 |
CVE-ID | CVE-2024-41110 CVE-2024-45337 CVE-2024-45338 CVE-2025-22869 CVE-2025-22870 CVE-2025-27144 |
CWE-ID | CWE-863 CWE-285 CWE-400 CWE-20 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #2 is available. |
Vulnerable software |
HPC Module Operating systems & Components / Operating system openSUSE Leap Operating systems & Components / Operating system SUSE Linux Enterprise Server 15 Operating systems & Components / Operating system apptainer-sle15_7 Operating systems & Components / Operating system package or component apptainer-leap Operating systems & Components / Operating system package or component apptainer-sle15_6 Operating systems & Components / Operating system package or component apptainer-sle15_5 Operating systems & Components / Operating system package or component apptainer Operating systems & Components / Operating system package or component apptainer-debuginfo Operating systems & Components / Operating system package or component |
Vendor | SUSE |
Security Bulletin
This security bulletin contains information about 6 vulnerabilities.
EUVDB-ID: #VU94762
Risk: Medium
CVSSv4.0: 7.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/U:Green]
CVE-ID: CVE-2024-41110
CWE-ID:
CWE-863 - Incorrect Authorization
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to AuthZ zero length regression. A remote user can bypass authentication and gain elevated privileges.
MitigationUpdate the affected package apptainer to the latest version.
Vulnerable software versionsHPC Module: 15-SP6
openSUSE Leap: 15.6
SUSE Linux Enterprise Server 15: SP6
apptainer-sle15_7: before 1.3.6-150600.4.9.1
apptainer-leap: before 1.3.6-150600.4.9.1
apptainer-sle15_6: before 1.3.6-150600.4.9.1
apptainer-sle15_5: before 1.3.6-150600.4.9.1
apptainer: before 1.3.6-150600.4.9.1
apptainer-debuginfo: before 1.3.6-150600.4.9.1
CPE2.3https://www.suse.com/support/update/announcement/2025/suse-su-20250980-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU101777
Risk: Medium
CVSSv4.0: 8.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/U:Green]
CVE-ID: CVE-2024-45337
CWE-ID:
CWE-285 - Improper Authorization
Exploit availability: Yes
DescriptionThe vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to improper authorization caused by improper usage of the ServerConfig.PublicKeyCallback callback. A remote attacker can bypass authorization in certain cases and gain access to the application.
Update the affected package apptainer to the latest version.
Vulnerable software versionsHPC Module: 15-SP6
openSUSE Leap: 15.6
SUSE Linux Enterprise Server 15: SP6
apptainer-sle15_7: before 1.3.6-150600.4.9.1
apptainer-leap: before 1.3.6-150600.4.9.1
apptainer-sle15_6: before 1.3.6-150600.4.9.1
apptainer-sle15_5: before 1.3.6-150600.4.9.1
apptainer: before 1.3.6-150600.4.9.1
apptainer-debuginfo: before 1.3.6-150600.4.9.1
CPE2.3https://www.suse.com/support/update/announcement/2025/suse-su-20250980-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.
EUVDB-ID: #VU101868
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-45338
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in several Parse functions. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
MitigationUpdate the affected package apptainer to the latest version.
Vulnerable software versionsHPC Module: 15-SP6
openSUSE Leap: 15.6
SUSE Linux Enterprise Server 15: SP6
apptainer-sle15_7: before 1.3.6-150600.4.9.1
apptainer-leap: before 1.3.6-150600.4.9.1
apptainer-sle15_6: before 1.3.6-150600.4.9.1
apptainer-sle15_5: before 1.3.6-150600.4.9.1
apptainer: before 1.3.6-150600.4.9.1
apptainer-debuginfo: before 1.3.6-150600.4.9.1
CPE2.3https://www.suse.com/support/update/announcement/2025/suse-su-20250980-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU105459
Risk: Low
CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-22869
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within the ssh package when handling clients that complete the key exchange slowly, or not at all. A remote user can trigger resource exhaustion and perform a denial of service (DoS) attack.
MitigationUpdate the affected package apptainer to the latest version.
Vulnerable software versionsHPC Module: 15-SP6
openSUSE Leap: 15.6
SUSE Linux Enterprise Server 15: SP6
apptainer-sle15_7: before 1.3.6-150600.4.9.1
apptainer-leap: before 1.3.6-150600.4.9.1
apptainer-sle15_6: before 1.3.6-150600.4.9.1
apptainer-sle15_5: before 1.3.6-150600.4.9.1
apptainer: before 1.3.6-150600.4.9.1
apptainer-debuginfo: before 1.3.6-150600.4.9.1
CPE2.3https://www.suse.com/support/update/announcement/2025/suse-su-20250980-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU106253
Risk: Medium
CVSSv4.0: 1.7 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-22870
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to alter application's behavior.
The vulnerability exists due to insufficient validation of an IPv6 zone ID as a hostname component, when matching hosts against proxy patterns. For instance the NO_PROXY environment variable is set to "*.example.com", a request to
"[::1%25.example.com]:80` will incorrectly match and not be proxied. A remote attacker can alter application behavior and potentially gain access to sensitive information or functionality.
Update the affected package apptainer to the latest version.
Vulnerable software versionsHPC Module: 15-SP6
openSUSE Leap: 15.6
SUSE Linux Enterprise Server 15: SP6
apptainer-sle15_7: before 1.3.6-150600.4.9.1
apptainer-leap: before 1.3.6-150600.4.9.1
apptainer-sle15_6: before 1.3.6-150600.4.9.1
apptainer-sle15_5: before 1.3.6-150600.4.9.1
apptainer: before 1.3.6-150600.4.9.1
apptainer-debuginfo: before 1.3.6-150600.4.9.1
CPE2.3https://www.suse.com/support/update/announcement/2025/suse-su-20250980-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU105450
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-27144
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing JWS and JWE input. A remote attacker can pass specially crafted data to the application, trigger resource exhaustion and perform a denial of service (DoS) attack.
MitigationUpdate the affected package apptainer to the latest version.
Vulnerable software versionsHPC Module: 15-SP6
openSUSE Leap: 15.6
SUSE Linux Enterprise Server 15: SP6
apptainer-sle15_7: before 1.3.6-150600.4.9.1
apptainer-leap: before 1.3.6-150600.4.9.1
apptainer-sle15_6: before 1.3.6-150600.4.9.1
apptainer-sle15_5: before 1.3.6-150600.4.9.1
apptainer: before 1.3.6-150600.4.9.1
apptainer-debuginfo: before 1.3.6-150600.4.9.1
CPE2.3https://www.suse.com/support/update/announcement/2025/suse-su-20250980-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.