
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-22034 is a security vulnerability in the osc package that was discovered and disclosed on October 16, 2024. The vulnerability affects various versions of osc across multiple Linux distributions including SUSE, Debian, and Ubuntu. The issue allows attackers to manipulate special files in the .osc directory, potentially affecting the package source configuration (SUSE Bugzilla).
The vulnerability allows attackers to put special files in .osc into the actual package sources (e.g., _apiurl), which enables them to modify the configuration of osc for the victim. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N (NVD).
When exploited, this vulnerability allows attackers to change the configuration of osc for the victim by manipulating special files in the .osc directory. This could lead to unauthorized configuration changes and potential security implications for package management operations (SUSE Bugzilla).
The vulnerability has been fixed in newer versions of the osc package. Debian has fixed the issue in version 1.12.1-1 for sid and trixie releases. SUSE has released security updates SUSE-SU-2024:2961-1 and SUSE-SU-2024:2963-1 to address this vulnerability. The fix involves putting all source files into a subdirectory to remove the root cause completely (SUSE Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."