cbcvebase.
CVE-2024-22034
published 2024-10-16

CVE-2024-22034: Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for…

medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim

Affected

19 ranges
VendorProductVersion rangeFixed in
debianosc< osc 1.9.0-1 (forky)osc 1.9.0-1 (forky)
opensuseosc>= 0 < 1.9.0-11.9.0-1
opensuseosc>= 0 < 1.9.0-11.9.0-1
suseopensuse_leap_15.5>= ? < 1.9.0-150400.10.6.11.9.0-150400.10.6.1
suseopensuse_leap_15.6>= ? < 1.9.0-150400.10.6.11.9.0-150400.10.6.1
suseopensuse_tumbleweed>= ? < 1.9.0-1.11.9.0-1.1
susesuse_linux_enterprise_desktop_15_sp5>= ? < 1.9.0-150400.10.6.11.9.0-150400.10.6.1
susesuse_linux_enterprise_desktop_15_sp6>= ? < 1.9.0-150400.10.6.11.9.0-150400.10.6.1
susesuse_linux_enterprise_high_performance_computing_15_sp5>= ? < 1.9.0-150400.10.6.11.9.0-150400.10.6.1
susesuse_linux_enterprise_high_performance_computing_15_sp6>= ? < 1.9.0-150400.10.6.11.9.0-150400.10.6.1
susesuse_linux_enterprise_module_for_development_tools_15_sp5>= ? < 1.9.0-150400.10.6.11.9.0-150400.10.6.1
susesuse_linux_enterprise_module_for_development_tools_15_sp6>= ? < 1.9.0-150400.10.6.11.9.0-150400.10.6.1
susesuse_linux_enterprise_server_12_sp5>= ? < 0.183.0-15.18.10.183.0-15.18.1
susesuse_linux_enterprise_server_15_sp5>= ? < 1.9.0-150400.10.6.11.9.0-150400.10.6.1
susesuse_linux_enterprise_server_15_sp6>= ? < 1.9.0-150400.10.6.11.9.0-150400.10.6.1
susesuse_linux_enterprise_server_for_sap_applications_12_sp5>= ? < 0.183.0-15.18.10.183.0-15.18.1
susesuse_linux_enterprise_server_for_sap_applications_15_sp5>= ? < 1.9.0-150400.10.6.11.9.0-150400.10.6.1
susesuse_linux_enterprise_server_for_sap_applications_15_sp6>= ? < 1.9.0-150400.10.6.11.9.0-150400.10.6.1
susesuse_linux_enterprise_software_development_kit_12_sp5>= ? < 0.183.0-15.18.10.183.0-15.18.1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv5.5MEDIUM