VDB
CVE-2024-22034
CVE-2024-22034
PUBLISHED
CVSS 5.5 MEDIUM
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
EPSS 0.21% · 11.2th percentile
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
0.21%
11.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SUSE | SUSE Linux Enterprise High Performance Computing 15 SP6 | ?, ? |
| SUSE | openSUSE Tumbleweed | ?, ? |
| SUSE | SUSE Linux Enterprise Desktop 15 SP5 | ?, ? |
| SUSE | openSUSE Leap 15.5 | ?, ? |
| SUSE | SUSE Linux Enterprise Software Development Kit 12 SP5 | *, ? |
| SUSE | SUSE Linux Enterprise High Performance Computing 15 SP5 | ?, ? |
| SUSE | SUSE Linux Enterprise Desktop 15 SP6 | *, ? |
| SUSE | SUSE Linux Enterprise Module for Development Tools 15 SP6 | ?, ? |
| SUSE | SUSE Linux Enterprise Server for SAP Applications 12 SP5 | ?, * |
| SUSE | SUSE Linux Enterprise Server 15 SP6 | ?, ? |
| SUSE | SUSE Linux Enterprise Server 12 SP5 | ?, ? |
| SUSE | openSUSE Leap 15.6 | ?, ? |
| SUSE | SUSE Linux Enterprise Server for SAP Applications 15 SP6 | ?, ? |
| SUSE | SUSE Linux Enterprise Server for SAP Applications 15 SP5 | ?, * |
| SUSE | SUSE Linux Enterprise Server 15 SP5 | ?, ? |
| SUSE | SUSE Linux Enterprise Module for Development Tools 15 SP5 | ?, ? |
Timeline
- Aug 20, 2024 CVE Published
- Oct 17, 2024 EPSS Score
- Oct 17, 2024 Coalition ESS Score
- Nov 5, 2024 EPSS Score
- Nov 23, 2024 EPSS Score
- Dec 13, 2024 EPSS Score
- Dec 31, 2024 EPSS Score
- Jan 19, 2025 EPSS Score
- Feb 7, 2025 EPSS Score
- Feb 25, 2025 EPSS Score
- Mar 16, 2025 EPSS Score
- Apr 4, 2025 EPSS Score