PT-2024-19168 · Osc+2 · Osc+2
Daniel Mach
+1
·
Published
2024-08-19
·
Updated
2024-10-16
·
CVE-2024-22034
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
osc (affected versions not specified)
Description
The issue allows attackers to manipulate the configuration of osc by injecting special files in .osc into the actual package sources, such as
apiurl. This enables the attacker to alter the osc configuration for the victim.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Suse
Osc