Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvp9-wx3h-666q

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.

In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.

EPSS

Процентиль: 63%
0.00451
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.7
ubuntu
почти 8 лет назад

In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.

CVSS3: 7.7
nvd
почти 8 лет назад

In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.

CVSS3: 7.7
debian
почти 8 лет назад

In libzypp before August 2018 GPG keys attached to YUM repositories we ...

suse-cvrf
больше 7 лет назад

Security update for libzypp, zypper

suse-cvrf
больше 7 лет назад

Security update for libzypp, zypper

EPSS

Процентиль: 63%
0.00451
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20