CVE-2018-12477: Opensuse Leap

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attackers to cause deletion of directories by tricking obs-service-refresh_patches to delete them. Affected releases are openSUSE Open Build Service: versions prior to d6244245dda5367767efc989446fe4b5e4609cce.

Affected products

  • Opensuse Leap: version 15.0 only; version 42.3 only

Published 2018-10-09. Last modified 2026-06-17.