2.1
CVSSv2

CVE-2017-9271

Published: 01/03/2018 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local malicious users to gain access to proxies used.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse zypper -

fedoraproject fedora 33

Vendor Advisories

Debian Bug report logs - #988152 CVE-2017-9271 Package: zypper; Maintainer for zypper is Mike Gabriel <sunweaver@debianorg>; Source for zypper is src:zypper (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 6 May 2021 17:48:02 UTC Severity: important Tags: security, upstream R ...