HIGH
kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwi_oemtitle of .profile."
Published Apr 16, 2014
7.5
HIGHCVSS 2.0
EPSS 1.50%
Description
Affected products
Remediation
References (1)
Change history (0)
No recorded changes yet.