CVE-2019-18900: Opensuse Libzypp
Low severity, CVSS 3.3. EPSS: 0.3% chance of exploitation in the next 30 days.
: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.0 libzypp versions prior to 16.21.2-27.68.1. SUSE Linux Enterprise Server 12 libzypp versions prior to 16.21.2-2.45.1. SUSE Linux Enterprise Server 15 17.19.0-3.34.1.
Affected products
- Opensuse Libzypp: before 16.21.2-27.68.1 (fixed in 16.21.2-27.68.1); before 16.21.2-2.45.1 (fixed in 16.21.2-2.45.1); before 17.19.0-3.34.1 (fixed in 17.19.0-3.34.1)
Published 2020-01-24. Last modified 2026-06-17.