Open Build Service, one year later: command execution through Mercurial argument injection
In March 2025 we published an analysis of a remote code execution vulnerability in Open Build Service (OBS), tracked as CVE-2024-22033. A little over a year later we went back to the same attack surface and found a second, distinct flaw of the same family. It has now been reported to the openSUSE security team and fixed…
Supply Chain Attacks on Linux distributions - OpenSUSE Open Build Service
Open Build Service (OBS) is an open-source distribution development platform provided by openSUSE. It allows developers to manage the whole packaging process in order to build a package from a simple software source and…
Supply Chain Attacks on Linux distributions - Fedora Pagure
As discussed in the meta-article, we picked Pagure from the Fedora Apps Directory and already had a technical approach in mind. A software forge is likely to be a good target for an argument injection: we can expect the…
Supply Chain Attacks on Linux distributions - Overview
Supply chain attacks have been a trendy topic in the past years. Rather than directly attacking their primary target, attackers infiltrate less secure assets, such as software dependencies, firmware, or service…