VulnerabilityModified
CVE-2011-0469
Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011.
CRITICAL 9.8EPSS 2.41%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.41% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- suse/opensuse
- Source
- security@opentext.com
References
- https://bugzilla.suse.com/show_bug.cgi?id=679325
- https://github.com/openSUSE/open-build-service/commit/23c8d21c75242999e29379e6ca8418a14c8725c6
- https://github.com/openSUSE/open-build-service/commit/76b0ab003f34435ca90d943e02dd22279cdeec2a
- https://bugzilla.suse.com/show_bug.cgi?id=679325
- https://github.com/openSUSE/open-build-service/commit/23c8d21c75242999e29379e6ca8418a14c8725c6
- https://github.com/openSUSE/open-build-service/commit/76b0ab003f34435ca90d943e02dd22279cdeec2a
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.