CVE-2017-9274: Opensuse Obs-Service-Source Validator
High severity, CVSS 7.8. EPSS: 2.3% chance of exploitation in the next 30 days.
A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.
Affected products
- Opensuse Obs-Service-Source Validator: before 0.7 (fixed in 0.7)
Published 2018-03-01. Last modified 2026-06-17.