openSUSE Vulnerabilities and Affected Products
Vulnerabilities associated with Tumbleweed.
Products
Clear product- Factory24 vulnerabilities
- Open Build Service13 vulnerabilities
- openSUSE Leap 15.113 vulnerabilities
- Leap 15.18 vulnerabilities
- Tumbleweed7 vulnerabilities
- openSUSE Leap 15.26 vulnerabilities
- openSUSE Leap 15.44 vulnerabilities
- leap3 vulnerabilities
- Leap 15.23 vulnerabilities
- openbuildservice3 vulnerabilities
- openSUSE Tumbleweed3 vulnerabilities
- libeconf2 vulnerabilities
- opensuse2 vulnerabilities
- openSUSE Backports SLE-15-SP32 vulnerabilities
- openSUSE Factory2 vulnerabilities
- openSUSE Leap 15.32 vulnerabilities
- Build service1 vulnerability
- buildservice1 vulnerability
- libsolv1 vulnerability
- obs-service-set_version1 vulnerability
- open-build-service1 vulnerability
- openSUSE Backports SLE-15-SP11 vulnerability
- openSUSE Backports SLE-15-SP21 vulnerability
- openSUSE Backports SLE-15-SP41 vulnerability
- openSUSE Leap Micro 5.21 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-53881MEDIUM | SUSE-specific logrotate configuration allows escalation from mail user/group to rootA UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalation from mail user/group to root.This issue affects Tumbleweed: from ? before 4.98.2-lp156.248.1. CWE-61Oct 2, 2025 | CVSS6.9v4.0 | EPSS0.157% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-46810HIGH | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate to root. This issue affects Tumbleweed: from ? before 2.11.29. CWE-61Sep 2, 2025 | CVSS8.5v4.0 | EPSS0.161% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49505MEDIUM | XSS vulnerability found in OpenSuse MirrorCacheA Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via reflected XSS in the REGEX and P parameters. This issue affects MirrorCache before 1.083. CWE-79Nov 13, 2024 | CVSS5.3v4.0 | EPSS0.322% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49506HIGH | Fixed temporary file path in aeon-checks allows fixing of disk encryption keyInsecure creation of temporary files allows local users on systems with non-default configurations to cause denial of service or set the encryption key for a filesystem CWE-377Nov 13, 2024 | CVSS7.3v4.0 | EPSS0.098% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-32183HIGH | Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root This issue affects openSUSE Tumbleweed. CWE-276Jul 7, 2023 | CVSS7.8v3.1 | EPSS0.209% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-31250HIGH | keylime %post scriplet allows for privilege escalation from keylime user to rootA UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escalate from the keylime user to root. This issue affects: openSUSE Tumbleweed keylime versions prior to 6.4.2-1.1. CWE-59Jul 20, 2022 | CVSS7.1v3.1 | EPSS0.322% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25315CRITICAL | salt-api unauthenticated remote code executionCWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002… | CVSS9.8v3.1 | EPSS2.33% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |