CVE-2018-12474
Last modified
CVE-2018-12474 is a vulnerability of currently unknown severity. Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: versions prior to 51a17c553b6ae2598820b7a90fd0c11502a49106.. EPSS estimates a 1.36% chance of exploitation in the next 30 days.
Description
Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: versions prior to 51a17c553b6ae2598820b7a90fd0c11502a49106.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opensuse | Tar Scm | < 0.9.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12474?
How severe is CVE-2018-12474?
How do I fix CVE-2018-12474?
Are you affected by CVE-2018-12474?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
