ZeroHour

CVE-2017-5188

CVSS 3.0
7.5 high
EPSS
1%p65
Published
()
Modified
Description

The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source directory during build, allowing leakage of private information.

Vendors
opensuse
Products
open build service
Weakness
CWE-59, CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.