VYPR

osc

by SUSE S.A.

CVEs (2)

  • CVE-2019-3681HigJun 29, 2020
    risk 0.49cvss 7.5epss 0.01

    A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE Linux Enterprise Software Development Kit 12-SP4; openSUSE Leap 15.1, openSUSE Factory allowed…

  • CVE-2024-22034MedOct 16, 2024
    risk 0.36cvss 5.5epss 0.00

    Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim