CVE-2017-9269: Opensuse Libzypp
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.
Affected products
- Opensuse Libzypp: affected versions not specified
Published 2018-03-01. Last modified 2026-06-17.