Vulnerabilities > Opensuse > TAR SCM > 0.2.3

DATE CVE VULNERABILITY TITLE RISK
2018-10-09 CVE-2018-12474 Improper Input Validation vulnerability in Opensuse TAR SCM
Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations.
network
low complexity
opensuse CWE-20
critical
9.8