← Back

Kiwi

kiwi

Vendor: Suse • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Suse
3Kiwi
Studio Extension For System ZStudio Onsite
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
kiwi before 4.98.05, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in an image name.
1Suse
3Kiwi
Studio Extension For System ZStudio Onsite
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwi_oemtitl...Show more
kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwi_oemtitle of .profile."Show less
1Suse
3Kiwi
Studio Extension For System ZStudio Onsite
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overl...Show more
kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.Show less