Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call.
| Software | From | Fixed in |
|---|---|---|
| marcus_schafer / kiwi | - | 3.74.1.x |
| novell / suse_studio_onsite | 1.1 | 1.1.x |