A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.
2018-03-01T20:29:01.007
2024-11-21T03:35:44.170
Modified
CVSSv3.0: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | opensuse | obs-service-source_validator | < 0.7 | Yes |