CVE-2024-22034
Crafted projects can overwrite special files in the .osc config directory
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5.5EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
16 out 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Produtos afetados
SUSE · openSUSE Leap 15.5SUSE · openSUSE Leap 15.6SUSE · openSUSE TumbleweedSUSE · SUSE Linux Enterprise Desktop 15 SP5SUSE · SUSE Linux Enterprise Desktop 15 SP6SUSE · SUSE Linux Enterprise High Performance Computing 15 SP5SUSE · SUSE Linux Enterprise High Performance Computing 15 SP6SUSE · SUSE Linux Enterprise Module for Development Tools 15 SP5SUSE · SUSE Linux Enterprise Module for Development Tools 15 SP6SUSE · SUSE Linux Enterprise Server 12 SP5SUSE · SUSE Linux Enterprise Server 15 SP5SUSE · SUSE Linux Enterprise Server 15 SP6SUSE · SUSE Linux Enterprise Server for SAP Applications 12 SP5SUSE · SUSE Linux Enterprise Server for SAP Applications 15 SP5SUSE · SUSE Linux Enterprise Server for SAP Applications 15 SP6SUSE · SUSE Linux Enterprise Software Development Kit 12 SP5Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →