CVE-2024-22034
published 2024-10-16CVE-2024-22034: Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for…
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
0.21%
11.1th percentile
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | osc | < osc 1.9.0-1 (forky) | osc 1.9.0-1 (forky) |
| opensuse | osc | >= 0 < 1.9.0-1 | 1.9.0-1 |
| opensuse | osc | >= 0 < 1.9.0-1 | 1.9.0-1 |
| suse | opensuse_leap_15.5 | >= ? < 1.9.0-150400.10.6.1 | 1.9.0-150400.10.6.1 |
| suse | opensuse_leap_15.6 | >= ? < 1.9.0-150400.10.6.1 | 1.9.0-150400.10.6.1 |
| suse | opensuse_tumbleweed | >= ? < 1.9.0-1.1 | 1.9.0-1.1 |
| suse | suse_linux_enterprise_desktop_15_sp5 | >= ? < 1.9.0-150400.10.6.1 | 1.9.0-150400.10.6.1 |
| suse | suse_linux_enterprise_desktop_15_sp6 | >= ? < 1.9.0-150400.10.6.1 | 1.9.0-150400.10.6.1 |
| suse | suse_linux_enterprise_high_performance_computing_15_sp5 | >= ? < 1.9.0-150400.10.6.1 | 1.9.0-150400.10.6.1 |
| suse | suse_linux_enterprise_high_performance_computing_15_sp6 | >= ? < 1.9.0-150400.10.6.1 | 1.9.0-150400.10.6.1 |
| suse | suse_linux_enterprise_module_for_development_tools_15_sp5 | >= ? < 1.9.0-150400.10.6.1 | 1.9.0-150400.10.6.1 |
| suse | suse_linux_enterprise_module_for_development_tools_15_sp6 | >= ? < 1.9.0-150400.10.6.1 | 1.9.0-150400.10.6.1 |
| suse | suse_linux_enterprise_server_12_sp5 | >= ? < 0.183.0-15.18.1 | 0.183.0-15.18.1 |
| suse | suse_linux_enterprise_server_15_sp5 | >= ? < 1.9.0-150400.10.6.1 | 1.9.0-150400.10.6.1 |
| suse | suse_linux_enterprise_server_15_sp6 | >= ? < 1.9.0-150400.10.6.1 | 1.9.0-150400.10.6.1 |
| suse | suse_linux_enterprise_server_for_sap_applications_12_sp5 | >= ? < 0.183.0-15.18.1 | 0.183.0-15.18.1 |
| suse | suse_linux_enterprise_server_for_sap_applications_15_sp5 | >= ? < 1.9.0-150400.10.6.1 | 1.9.0-150400.10.6.1 |
| suse | suse_linux_enterprise_server_for_sap_applications_15_sp6 | >= ? < 1.9.0-150400.10.6.1 | 1.9.0-150400.10.6.1 |
| suse | suse_linux_enterprise_software_development_kit_12_sp5 | >= ? < 0.183.0-15.18.1 | 0.183.0-15.18.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-22034: osc - Attackers could put the special files in .osc into the actual package sources (e...
vendor_debian·2024·CVSS 5.5
CVE-2024-22034 [MEDIUM] CVE-2024-22034: osc - Attackers could put the special files in .osc into the actual package sources (e...
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.9.0-1)
sid: resolved (fixed in 1.9.0-1)
trixie: resolved (fixed in 1.9.0-1)
OSV
CVE-2024-22034: Attackers could put the special files in
osv·2024-10-16·CVSS 5.5
CVE-2024-22034 [MEDIUM] CVE-2024-22034: Attackers could put the special files in
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
GHSA
GHSA-gm3v-m2w5-wm38: Attackers could put the special files in
ghsa_unreviewed·2024-10-16
CVE-2024-22034 [MEDIUM] GHSA-gm3v-m2w5-wm38: Attackers could put the special files in
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-16
Published