CVE-2023-22643: libzypp-plugin-appdata: potential arbitrary code execution via shell injection due to `os.system` calls
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in libzypp-plugin-appdata of SUSE Linux Enterprise Server for SAP 15-SP3; openSUSE Leap 15.4 allows attackers that can trick users to use specially crafted REPOALIAS, REPOTYPE or REPOMETADATAPATH settings to execute code as root. This issue affects: SUSE Linux Enterprise Server for SAP 15-SP3 libzypp-plugin-appdata versions prior to 1.0.1+git.20180426. openSUSE Leap 15.4 libzypp-plugin-appdata versions prior to 1.0.1+git.20180426.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-22643.
What is the title of the vulnerability?
The title of the vulnerability is 'An Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in libzypp-plugin-appdata of SUSE Linux Enterprise Server for SAP 15-SP3; openSUSE Leap 15.4'.
What is the severity of CVE-2023-22643?
The severity of CVE-2023-22643 is high with a severity value of 7.8.
Which software is affected by CVE-2023-22643?
The software affected by CVE-2023-22643 is Opensuse Libzypp-plugin-appdata, openSUSE Leap 15.4, and SUSE Linux Enterprise Server for SAP 15-SP3.
How can the OS Command Injection vulnerability in libzypp-plugin-appdata be exploited?
The OS Command Injection vulnerability in libzypp-plugin-appdata can be exploited by tricking users to use specially crafted REPO_ALIAS, REPO_TYPE or REPO_METADATA.