cbcvebase.
CVE-2017-9274
published 2018-03-01

CVE-2017-9274: A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with…

high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianosc< osc 0.162.1-1 (bookworm)osc 0.162.1-1 (bookworm)
opensuseobs-service-source_validator< 0.70.7
opensuseosc>= 0 < 0.162.1-10.162.1-1
opensuseosc>= 0 < 0.162.1-10.162.1-1
opensuseosc>= 0 < 0.162.1-10.162.1-1
opensuseosc>= 0 < 0.162.1-10.162.1-1
suseobs-service-source_validator>= unspecified < 0.70.7

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH