{"api_version":"1","generated_at":"2026-04-23T04:21:11+00:00","cve":"CVE-2017-7435","urls":{"html":"https://cve.report/CVE-2017-7435","api":"https://cve.report/api/cve/CVE-2017-7435.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-7435","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-7435"},"summary":{"title":"CVE-2017-7435","description":"In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.","state":"PUBLIC","assigner":"security@microfocus.com","published_at":"2018-03-01 20:29:00","updated_at":"2023-11-07 02:50:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://www.suse.com/de-de/security/cve/CVE-2017-7435/","name":"https://www.suse.com/de-de/security/cve/CVE-2017-7435/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"CVE-2017-7435 | SUSE","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1009127","name":"https://bugzilla.suse.com/show_bug.cgi?id=1009127","refsource":"","tags":[],"title":"Bug 1009127 – AUDIT-0: VUL-0: unsigned 3rd party repo accepted without warning","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html","name":"SUSE-SU-2017:2040","refsource":"SUSE","tags":["Vendor Advisory"],"title":"[security-announce] SUSE-SU-2017:2040-1: important: Security update for","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-7435","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7435","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Ludwig Nussel of SUSE","lang":""}],"nvd_cpes":[{"cve_year":"2017","cve_id":"7435","vulnerable":"1","versionEndIncluding":"16.15.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opensuse","cpe5":"libzypp","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@microfocus.com","DATE_PUBLIC":"2017-08-03T00:00:00.000Z","ID":"CVE-2017-7435","STATE":"PUBLIC","TITLE":"libzypp accepts unsigned 3rd party repo without warning"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"libzypp","version":{"version_data":[{"affected":"<","version_value":"20170803"}]}}]},"vendor_name":"SUSE"}]}},"credit":[{"lang":"eng","value":"Ludwig Nussel of SUSE"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system."}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Missing UI interaction when adding untrusted repositories could lead to use of unsigned package repositories."}]}]},"references":{"reference_data":[{"name":"SUSE-SU-2017:2040","refsource":"SUSE","url":"https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html"},{"name":"https://www.suse.com/de-de/security/cve/CVE-2017-7435/","refsource":"CONFIRM","url":"https://www.suse.com/de-de/security/cve/CVE-2017-7435/"},{"name":"https://bugzilla.suse.com/show_bug.cgi?id=1009127","refsource":"CONFIRM","url":"https://bugzilla.suse.com/show_bug.cgi?id=1009127"}]},"source":{"advisory":"https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html","defect":["https://bugzilla.suse.com/show_bug.cgi?id=1009127"],"discovery":"INTERNAL"}},"nvd":{"publishedDate":"2018-03-01 20:29:00","lastModifiedDate":"2023-11-07 02:50:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9.3},"severity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:opensuse:libzypp:*:*:*:*:*:*:*:*","versionEndIncluding":"16.15.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"7435","Ordinal":"104239","Title":"CVE-2017-7435","CVE":"CVE-2017-7435","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"7435","Ordinal":"1","NoteData":"In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"7435","Ordinal":"2","NoteData":"2018-03-01","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"7435","Ordinal":"3","NoteData":"2021-01-06","Type":"Other","Title":"Modified"}]}}}