CRITICAL9.8CVE-2019-3681A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterpris…
from 0, < 0.169.1-1
HIGH7.8CVE-2017-9274A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SP…
from 0, < 0.162.1-1
MEDIUM5.5CVE-2024-22034Attackers could put the special files in .osc into the actual package sources (e.g.
from 0
—osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.
from 0, < 0.149.0-2
—osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log…