Attackers can inject malicious files into osc package sources

CVE-2024-22034
5.5MEDIUM

Key Information

Vendor
Suse
Status
Suse Linux Enterprise Desktop 15 Sp5
Suse Linux Enterprise High Performance Computing 15 Sp5
Suse Linux Enterprise Module For Development Tools 15 Sp5
Suse Linux Enterprise Server 15 Sp5
Vendor
CVE Published:
16 October 2024

Summary

Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim

Affected Version(s)

SUSE Linux Enterprise Desktop 15 SP5 < 1.9.0-150400.10.6.1

SUSE Linux Enterprise High Performance Computing 15 SP5 < 1.9.0-150400.10.6.1

SUSE Linux Enterprise Module for Development Tools 15 SP5 < 1.9.0-150400.10.6.1

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Daniel Mach of SUSE
.