CVE-2018-12477: Opensuse Leap
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attackers to cause deletion of directories by tricking obs-service-refresh_patches to delete them. Affected releases are openSUSE Open Build Service: versions prior to d6244245dda5367767efc989446fe4b5e4609cce.
Affected products
- Opensuse Leap: version 15.0 only; version 42.3 only
Published 2018-10-09. Last modified 2026-06-17.