Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gvfg-vcp7-gmf9

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.

In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.

EPSS

Процентиль: 66%
0.00521
Низкий

8.1 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 8 лет назад

In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.

CVSS3: 8.1
nvd
почти 8 лет назад

In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.

CVSS3: 8.1
debian
почти 8 лет назад

In libzypp before 20170803 it was possible to add unsigned YUM reposit ...

suse-cvrf
больше 8 лет назад

Security update for libzypp

suse-cvrf
больше 8 лет назад

Security update for libzypp, zypper

EPSS

Процентиль: 66%
0.00521
Низкий

8.1 High

CVSS3

Дефекты

CWE-20