CVE-2024-22034: Suse Opensuse Leap 15.5

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim

Affected products

  • Suse Opensuse Leap 15.5
  • Suse Opensuse Leap 15.6
  • Suse Opensuse Tumbleweed
  • Suse Suse Linux Enterprise Desktop 15 SP5
  • Suse Suse Linux Enterprise Desktop 15 SP6
  • Suse Suse Linux Enterprise High Performance Computing 15 SP5
  • Suse Suse Linux Enterprise High Performance Computing 15 SP6
  • Suse Suse Linux Enterprise Module For Development Tools 15 SP5
  • Suse Suse Linux Enterprise Module For Development Tools 15 SP6
  • Suse Suse Linux Enterprise Server 12 SP5
  • Suse Suse Linux Enterprise Server 15 SP5
  • Suse Suse Linux Enterprise Server 15 SP6
  • Suse Suse Linux Enterprise Server For SAP Applications 12 SP5
  • Suse Suse Linux Enterprise Server For SAP Applications 15 SP5
  • Suse Suse Linux Enterprise Server For SAP Applications 15 SP6
  • Suse Suse Linux Enterprise Software Development Kit 12 SP5

Published 2024-10-16. Last modified 2026-06-17.