The Sos Project maintains a diagnostic and log-collection utility that gathers system information for troubleshooting purposes, with a narrow but strategically positioned footprint. Its vulnerabilities center on information-disclosure and file-access issues, reflecting the sensitive nature of diagnostic data that such tools routinely handle and the file-system operations inherent to log aggregation. Current vulnerability counts and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sos Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5392MEDIUM XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or dir | Sep 23, 2014 | 5.8 | 22 | NO | NO |
CVE-2022-2806MEDIUM It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev | Sep 1, 2022 | 5.5 | 20 | NO | NO |
CVE-2015-7529HIGH sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as | Nov 6, 2017 | 7.8 | 20 | NO | NO |
CVE-2014-5391MEDIUM Cross-site scripting (XSS) vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote attackers to inject | Sep 11, 2014 | 4.3 | 19 | NO | NO |
CVE-2014-5393MEDIUM Directory traversal vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote authenticated users with t | Sep 11, 2014 | 4.0 | 18 | NO | NO |
CVE-2015-3171MEDIUM sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of t | Jul 25, 2017 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sos Project.
Media articles that mention a CVE ID that affects a product developed by Sos Project — matched by CVE ID, not by vendor name.