CVE-2024-22034
Crafted projects can overwrite special files in the .osc config directory
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Productos afectados
SUSE · openSUSE Leap 15.5SUSE · openSUSE Leap 15.6SUSE · openSUSE TumbleweedSUSE · SUSE Linux Enterprise Desktop 15 SP5SUSE · SUSE Linux Enterprise Desktop 15 SP6SUSE · SUSE Linux Enterprise High Performance Computing 15 SP5SUSE · SUSE Linux Enterprise High Performance Computing 15 SP6SUSE · SUSE Linux Enterprise Module for Development Tools 15 SP5SUSE · SUSE Linux Enterprise Module for Development Tools 15 SP6SUSE · SUSE Linux Enterprise Server 12 SP5SUSE · SUSE Linux Enterprise Server 15 SP5SUSE · SUSE Linux Enterprise Server 15 SP6SUSE · SUSE Linux Enterprise Server for SAP Applications 12 SP5SUSE · SUSE Linux Enterprise Server for SAP Applications 15 SP5SUSE · SUSE Linux Enterprise Server for SAP Applications 15 SP6SUSE · SUSE Linux Enterprise Software Development Kit 12 SP5¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →