Описание
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 1.12.1-2 |
| esm-apps/bionic | needs-triage | |
| esm-apps/focal | needs-triage | |
| esm-apps/jammy | needs-triage | |
| esm-apps/noble | needs-triage | |
| esm-apps/xenial | needs-triage | |
| focal | ignored | end of standard support, was needs-triage |
| jammy | needs-triage | |
| noble | needs-triage | |
| oracular | ignored | end of life, was needs-triage |
Показывать по
10
EPSS
Процентиль: 5%
0.00021
Низкий
5.5 Medium
CVSS3
Связанные уязвимости
CVSS3: 5.5
nvd
больше 1 года назад
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
CVSS3: 5.5
debian
больше 1 года назад
Attackers could put the special files in .osc into the actual package ...
CVSS3: 5.5
github
больше 1 года назад
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
EPSS
Процентиль: 5%
0.00021
Низкий
5.5 Medium
CVSS3