← Back

Studio Extension For System Z

studio_extension_for_system_z

Vendor: Suse • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Suse
3Kiwi
Studio Extension For System ZStudio Onsite
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
kiwi before 4.98.05, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in an image name.
1Suse
2Studio Extension For System Z
Studio Onsite
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the overlay files tab in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1 allows remote attackers to inject arbitrary web script or H...Show more
Cross-site scripting (XSS) vulnerability in the overlay files tab in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted application, related to cloning.Show less
1Suse
3Kiwi
Studio Extension For System ZStudio Onsite
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwi_oemtitl...Show more
kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwi_oemtitle of .profile."Show less
1Suse
3Kiwi
Studio Extension For System ZStudio Onsite
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overl...Show more
kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.Show less
1Suse
2Studio Extension For System Z
Studio Onsite
Apr 29, 2026
Feb 26, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vectors.