CVE-2017-9271
published 2018-03-01CVE-2017-9271: The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.34%
25.9th percentile
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libzypp | < libzypp 17.25.5-2 (bookworm) | libzypp 17.25.5-2 (bookworm) |
| fedoraproject | fedora | — | — |
| suse | zypper | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv3.04.0MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q4p8-c668-h326: The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used
ghsa_unreviewed·2022-05-13
CVE-2017-9271 [LOW] CWE-532 GHSA-q4p8-c668-h326: The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
OSV
CVE-2017-9271: The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used
osv·2018-03-01·CVSS 3.3
CVE-2017-9271 [LOW] CVE-2017-9271: The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
Debian
CVE-2017-9271: libzypp - The commandline package update tool zypper writes HTTP proxy credentials into it...
vendor_debian·2017·CVSS 3.3
CVE-2017-9271 [LOW] CVE-2017-9271: libzypp - The commandline package update tool zypper writes HTTP proxy credentials into it...
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
Scope: local
bookworm: resolved (fixed in 17.25.5-2)
bullseye: resolved (fixed in 17.25.5-2)
forky: resolved (fixed in 17.25.5-2)
sid: resolved (fixed in 17.25.5-2)
trixie: resolved (fixed in 17.25.5-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.suse.com/show_bug.cgi?id=1050625https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VP2DNHXEQFHXBCTSREPNR7BU4EX64SQG/https://www.suse.com/de-de/security/cve/CVE-2017-9271/https://bugzilla.suse.com/show_bug.cgi?id=1050625https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VP2DNHXEQFHXBCTSREPNR7BU4EX64SQG/https://www.suse.com/de-de/security/cve/CVE-2017-9271/
2018-03-01
Published