lnussel/kiwi

lnussel/kiwi

GitHubGitHub
Unavailable
This project is no longer available (or publicly accessible) from GitHub
Releases100
Frequency5 days 1 hour
Last Release
KIWI - Appliance Builder Next Generation

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

kiwi before 4.98.05, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in an image name.

7.5 HIGH

kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.