CVE-2024-22034

MEDIUM

SUSE Linux Enterprise Desktop 15 SP5 - Arbitrary Configuration Manipulation via .osc Special Files

Title source: llm
STIX 2.1

Description

Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim

References (1)

Core 1

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 6.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (16)
SUSE/openSUSE Leap 15.5 ? - 1.9.0-150400.10.6.1
SUSE/openSUSE Leap 15.6 ? - 1.9.0-150400.10.6.1
SUSE/openSUSE Tumbleweed ? - 1.9.0-1.1
SUSE/SUSE Linux Enterprise Desktop 15 SP5 ? - 1.9.0-150400.10.6.1
SUSE/SUSE Linux Enterprise Desktop 15 SP6 ? - 1.9.0-150400.10.6.1
SUSE/SUSE Linux Enterprise High Performance Computing 15 SP5 ? - 1.9.0-150400.10.6.1
SUSE/SUSE Linux Enterprise High Performance Computing 15 SP6 ? - 1.9.0-150400.10.6.1
SUSE/SUSE Linux Enterprise Module for Development Tools 15 SP5 ? - 1.9.0-150400.10.6.1
SUSE/SUSE Linux Enterprise Module for Development Tools 15 SP6 ? - 1.9.0-150400.10.6.1
SUSE/SUSE Linux Enterprise Server 12 SP5 ? - 0.183.0-15.18.1
... and 6 more
Published Oct 16, 2024
Tracked Since Feb 18, 2026