Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m2f8-w9q8-gvj5

Опубликовано: 18 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

EPSS

Процентиль: 34%
0.00417
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-24

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 месяцев назад

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

CVSS3: 6.5
redhat
около 2 месяцев назад

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

CVSS3: 6.5
nvd
около 2 месяцев назад

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

CVSS3: 6.5
debian
около 2 месяцев назад

A path traversal in handling the "path" component of .repo files proce ...

suse-cvrf
около 1 месяца назад

Security update for libzypp

EPSS

Процентиль: 34%
0.00417
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-24