Attackers can inject malicious files into osc package sources
CVE-2024-22034
5.5MEDIUM
Key Information
- Vendor
- Suse
- Status
- Suse Linux Enterprise Desktop 15 Sp5
- Suse Linux Enterprise High Performance Computing 15 Sp5
- Suse Linux Enterprise Module For Development Tools 15 Sp5
- Suse Linux Enterprise Server 15 Sp5
- Vendor
- CVE Published:
- 16 October 2024
Summary
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
Affected Version(s)
SUSE Linux Enterprise Desktop 15 SP5 < 1.9.0-150400.10.6.1
SUSE Linux Enterprise High Performance Computing 15 SP5 < 1.9.0-150400.10.6.1
SUSE Linux Enterprise Module for Development Tools 15 SP5 < 1.9.0-150400.10.6.1
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database
Credit
Daniel Mach of SUSE