« Volver al listado

CVE-2024-22033

Estado: AplazadaMedia (5.1)—

The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide a configuration to the service that allowed to execute command in later steps

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-22033",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-22033",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-16T14:07:38.141746Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "meissner@suse.de",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "meissner@suse.de",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 5.1,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "PASSIVE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "LOW",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "LOW",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "LOW",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "meissner@suse.de",
      "affectedData": [
        {
          "vendor": "SUSE",
          "product": "SUSE Package Hub 15 SP5",
          "versions": [
            {
              "status": "affected",
              "version": "?",
              "lessThan": "0.2.1-bp155.3.3.1",
              "versionType": "custom"
            }
          ],
          "packageName": "obs-service-download_url",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "SUSE",
          "product": "SUSE Package Hub 15 SP6",
          "versions": [
            {
              "status": "affected",
              "version": "?",
              "lessThan": "0.2.1-bp156.2.3.1",
              "versionType": "custom"
            }
          ],
          "packageName": "obs-service-download_url",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "SUSE",
          "product": "openSUSE Leap 15.5",
          "versions": [
            {
              "status": "affected",
              "version": "?",
              "lessThan": "0.2.1-bp155.3.3.1",
              "versionType": "custom"
            }
          ],
          "packageName": "obs-service-download_url",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "SUSE",
          "product": "openSUSE Leap 15.6",
          "versions": [
            {
              "status": "affected",
              "version": "?",
              "lessThan": "0.2.1-bp156.2.3.1",
              "versionType": "custom"
            }
          ],
          "packageName": "obs-service-download_url",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "SUSE",
          "product": "openSUSE Tumbleweed",
          "versions": [
            {
              "status": "affected",
              "version": "?",
              "lessThan": "0.2.1-1.1",
              "versionType": "custom"
            }
          ],
          "packageName": "obs-service-download_url",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-10-16T14:15:05.280",
  "references": [
    {
      "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-22033",
      "source": "meissner@suse.de"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "meissner@suse.de",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide a configuration to the service that allowed to execute command in later steps"
    },
    {
      "lang": "es",
      "value": "El servicio OBS obs-service-download_url era vulnerable a una vulnerabilidad de inyección de comandos. El atacante podría proporcionar una configuración al servicio que permitiera ejecutar comandos en pasos posteriores."
    }
  ],
  "lastModified": "2026-06-17T07:10:34.790",
  "sourceIdentifier": "meissner@suse.de"
}