CVE-2017-9274: Opensuse Obs-Service-Source Validator

High severity, CVSS 7.8. EPSS: 2.3% chance of exploitation in the next 30 days.

A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.

Affected products

  • Opensuse Obs-Service-Source Validator: before 0.7 (fixed in 0.7)

Published 2018-03-01. Last modified 2026-06-17.