cbcvebase.

Opensuse Osc vulnerabilities

5 known vulnerabilities affecting opensuse/osc.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2019-3681P2CRITICALCVSS 9.8fixed in 0.169.1-3.20.1fixed in 0.162.1-15.9.1+2 more2020-06-29
CVE-2019-3681 [CRITICAL] CWE-73 CVE-2019-3681: A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Dev A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE Linux Enterprise Software Development Kit 12-SP4; openSUSE Leap 15.1, openSUSE Factory allowed remote attackers that can change downloaded packages to overwrite arbitrary fi
nvdosv
CVE-2015-0778P3HIGHCVSS 7.5≥ 0, < 0.149.0-22015-03-16
CVE-2015-0778 [HIGH] CVE-2015-0778: osc before 0 osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.
osv
CVE-2017-9274P3HIGHCVSS 7.8≥ 0, < 0.162.1-12018-03-01
CVE-2017-9274 [HIGH] CVE-2017-9274: A shell command injection in the obs-service-source_validator before 0 A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.
osv
CVE-2012-1095P4MEDIUMCVSS 4.3≤ 0.1332014-02-06
CVE-2012-1095 [MEDIUM] CWE-264 CVE-2012-1095: osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitra osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.
nvdosv
CVE-2024-22034P4MEDIUMCVSS 5.5≥ 0, < 1.9.0-12024-10-16
CVE-2024-22034 [MEDIUM] CVE-2024-22034: Attackers could put the special files in Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
osv
Opensuse Osc vulnerabilities | cvebase