In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.
2018-03-01T20:29:00.820
2024-11-21T03:35:43.547
Modified
CVSSv3.0: 7.7 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4