CVE-2023-32184: Opensuse Welcome

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute code as the user that runs opensuse-welcome if a custom layout is chosen This issue affects opensuse-welcome: from 0.1 before 0.1.9+git.35.4b9444a.

Affected products

  • Opensuse Welcome: from 0.1.0, before 0.1.9\+git.35.4b9444a (fixed in 0.1.9\+git.35.4b9444a)

Published 2023-09-19. Last modified 2026-06-17.