Micro Focus openSUSE是英国Micro Focus公司的一套基于Linux的自由操作系统。NextCloud是使用在其中的一个私有云搭建软件。 Micro Focus openSUSE中的NextCloud存在安全漏洞,该漏洞源于程序没有安全的使用/srv/www/htdocs。在nextcloud包升级过程中,攻击者可利用该漏洞以wwwrun用户身份运行脚本,将权限提升至root。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-14798 | local privilege escalation in SUSE postgresql init script | |
| CVE-2017-14804 | package builds could use directory traversal to write outside of target area | |
| CVE-2017-7435 | libzypp accepts unsigned 3rd party repo without warning | |
| CVE-2017-7436 | libzypp accepts unsigned packages even when configured to check signatures | |
| CVE-2017-9268 | open-build-service retrigger / wipebinaries hitting the wrong project bypassing access per | |
| CVE-2017-9269 | lack of keypinning in libzypp could lead to repository switching | |
| CVE-2017-9270 | post-auth arbitrary file write on cryptctl server | |
| CVE-2017-9271 | proxy credentials written to log files by zypper | |
| CVE-2017-9274 | osc executes spec code during "osc commit" |
No comments yet