目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

opensuse 厂商漏洞列表 / CVE 中文分析 52

opensuse 厂商相关 52 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

openSUSE 是面向开发者和系统管理员的开源 Linux 发行版,核心用途在于提供稳定且可定制的基础设施环境。其历史漏洞多集中于权限提升、远程代码执行及本地信息泄露,常源于内核组件或系统工具的配置缺陷。值得关注的是,该项目采用开放协作模式,通过 OBS 构建系统强化软件供应链安全,并定期发布安全公告以修复关键风险,截至最新统计已收录 50 条 CVE,体现了其在企业级应用中的持续安全维护能力。

CVE IDタイトルCVSS深刻度公開日
CVE-2020-8021 unauthorized read access to files where sourceaccess is disabled via a crafted _service file in Open Build Service — Open Build ServiceCWE-269 5.3 Medium2020-05-19
CVE-2020-8020 Persistent XSS in markdown parser used by obs-server — open-build-serviceCWE-79 6.5 Medium2020-05-13
CVE-2020-8015 Local privilege escalation in exim package from user mail to root — FactoryCWE-59 8.4 High2020-04-02
CVE-2019-3700 yast: Fallback to DES without configuration in /etc/login.def — FactoryCWE-327 2.9 Low2020-01-24
CVE-2019-3699 Local privilege escalation from user privoxy to root — Leap 15.1CWE-59 7.7 High2020-01-24
CVE-2019-3697 Local privilege escalation from user gnump3d to root — Leap 15.1CWE-59 7.7 High2020-01-24
CVE-2019-3694 Local privilege escalation from munin to root in the packaging of munin — FactoryCWE-59 7.7 High2020-01-24
CVE-2019-18899 apt-cacher-ng insecure use of /run/apt-cacher-ng — Leap 15.1CWE-269 6.2 Medium2020-01-23
CVE-2018-12479 Request controller allows to create requests with arbitrary request IDs — Open Build ServiceCWE-20 7.5 -2018-10-09
CVE-2018-12478 obs-service-replace_using_package_version allows to specify arbitrary input files — Open Build ServiceCWE-20 6.5 -2018-10-09
CVE-2018-12477 obs-service-refresh_patches can be tricked into deleting '..' or other unrelated directories — Open Build ServiceCWE-93 6.5 -2018-10-09
CVE-2018-12474 Crafted service parameters allows to induce unexpected behaviour in obs-service-tar_scm — Open Build ServiceCWE-20 8.8 -2018-10-09
CVE-2018-12473 path traversal in obs-service-tar_scm — Open Build ServiceCWE-23 7.5 -2018-10-02
CVE-2018-12467 delete package via link exploit in open buildservice — openbuildserviceCWE-285 7.5 -2018-08-01
CVE-2018-12466 openbuildservice allowed deleting packages via project links — openbuildserviceCWE-285 6.5 -2018-08-01
CVE-2014-0593 sed command injection — obs-service-set_versionCWE-78 9.8 -2018-06-08
CVE-2014-0594 CSRF protection incorrectly disabled — Open Build ServiceCWE-352 8.8 -2018-06-08
CVE-2013-3703 No write permission check in change_role command — Open Build ServiceCWE-862 6.5 -2018-06-08
CVE-2018-7688 Open Build Service accepts arbitrary reviews — Open Build ServiceCWE-862 6.5 -2018-06-07
CVE-2018-7689 Open Build Service arbitrary package modification — Open Build ServiceCWE-862 6.5 -2018-06-07
CVE-2011-3178 openbuildservice webui code injection — openbuildservice 8.8 -2018-03-20
CVE-2017-5188 OBS worker VM escape via relative symbolic links — open build service 6.5 -2018-03-01

本页汇总了 opensuse 厂商截至目前公开的全部 52 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。