Show plain JSON{"containers": {"cna": {"affected": [{"product": "libzypp", "vendor": "SUSE", "versions": [{"lessThan": "20170803", "status": "affected", "version": "unspecified", "versionType": "custom"}]}], "credits": [{"lang": "en", "value": "Ludwig Nussel of SUSE"}], "datePublic": "2017-08-03T00:00:00", "descriptions": [{"lang": "en", "value": "In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system."}], "metrics": [{"cvssV3_0": {"attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.1, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0"}}], "problemTypes": [{"descriptions": [{"description": "Missing UI interaction when adding untrusted repositories could lead to use of unsigned package repositories.", "lang": "en", "type": "text"}]}], "providerMetadata": {"dateUpdated": "2021-01-06T16:16:05", "orgId": "f81092c5-7f14-476d-80dc-24857f90be84", "shortName": "microfocus"}, "references": [{"name": "SUSE-SU-2017:2040", "tags": ["vendor-advisory", "x_refsource_SUSE"], "url": "https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html"}, {"tags": ["x_refsource_CONFIRM"], "url": "https://www.suse.com/de-de/security/cve/CVE-2017-7435/"}, {"tags": ["x_refsource_CONFIRM"], "url": "https://bugzilla.suse.com/show_bug.cgi?id=1009127"}], "source": {"advisory": "https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html", "defect": ["https://bugzilla.suse.com/show_bug.cgi?id=1009127"], "discovery": "INTERNAL"}, "title": "libzypp accepts unsigned 3rd party repo without warning", "x_legacyV4Record": {"CVE_data_meta": {"ASSIGNER": "security@microfocus.com", "DATE_PUBLIC": "2017-08-03T00:00:00.000Z", "ID": "CVE-2017-7435", "STATE": "PUBLIC", "TITLE": "libzypp accepts unsigned 3rd party repo without warning"}, "affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"product_name": "libzypp", "version": {"version_data": [{"affected": "<", "version_affected": "<", "version_value": "20170803"}]}}]}, "vendor_name": "SUSE"}]}}, "credit": [{"lang": "eng", "value": "Ludwig Nussel of SUSE"}], "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": {"description_data": [{"lang": "eng", "value": "In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system."}]}, "impact": {"cvss": {"attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.1, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0"}}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "Missing UI interaction when adding untrusted repositories could lead to use of unsigned package repositories."}]}]}, "references": {"reference_data": [{"name": "SUSE-SU-2017:2040", "refsource": "SUSE", "url": "https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html"}, {"name": "https://www.suse.com/de-de/security/cve/CVE-2017-7435/", "refsource": "CONFIRM", "url": "https://www.suse.com/de-de/security/cve/CVE-2017-7435/"}, {"name": "https://bugzilla.suse.com/show_bug.cgi?id=1009127", "refsource": "CONFIRM", "url": "https://bugzilla.suse.com/show_bug.cgi?id=1009127"}]}, "source": {"advisory": "https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html", "defect": ["https://bugzilla.suse.com/show_bug.cgi?id=1009127"], "discovery": "INTERNAL"}}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-05T16:04:11.255Z"}, "title": "CVE Program Container", "references": [{"name": "SUSE-SU-2017:2040", "tags": ["vendor-advisory", "x_refsource_SUSE", "x_transferred"], "url": "https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "https://www.suse.com/de-de/security/cve/CVE-2017-7435/"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "https://bugzilla.suse.com/show_bug.cgi?id=1009127"}]}]}, "cveMetadata": {"assignerOrgId": "f81092c5-7f14-476d-80dc-24857f90be84", "assignerShortName": "microfocus", "cveId": "CVE-2017-7435", "datePublished": "2018-03-01T19:00:00Z", "dateReserved": "2017-04-05T00:00:00", "dateUpdated": "2024-09-16T22:14:57.477Z", "state": "PUBLISHED"}, "dataType": "CVE_RECORD", "dataVersion": "5.1"}