CVE-2018-12476: Suse Obs-Service-Tar Scm
High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.
Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user if a malicious service is executed. This issue affects: SUSE Linux Enterprise Server 15 obs-service-tar_scm versions prior to 0.9.2.1537788075.fefaa74:. openSUSE Factory obs-service-tar_scm versions prior to 0.9.2.1537788075.fefaa74.
Affected products
- Suse Obs-Service-Tar Scm: before 0.9.2.1537788075.fefaa74 (fixed in 0.9.2.1537788075.fefaa74)
Published 2020-01-27. Last modified 2026-06-17.