CVE-2018-7688

A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opensuse:open_build_service:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:12

Type Values Removed Values Added
CVSS v2 : 4.0
v3 : 6.5
v2 : 4.0
v3 : 7.1
References () https://bugzilla.suse.com/show_bug.cgi?id=CVE-2018-7688 - () https://bugzilla.suse.com/show_bug.cgi?id=CVE-2018-7688 -
References () https://github.com/openSUSE/open-build-service/commit/b15cf19e9e01115f653c76ffdc8f54cd97566553 - () https://github.com/openSUSE/open-build-service/commit/b15cf19e9e01115f653c76ffdc8f54cd97566553 -
References () https://lists.opensuse.org/opensuse-buildservice/2018-06/msg00014.html - () https://lists.opensuse.org/opensuse-buildservice/2018-06/msg00014.html -

07 Nov 2023, 03:01

Type Values Removed Values Added
References (CONFIRM) https://bugzilla.suse.com/show_bug.cgi?id=CVE-2018-7688 - Issue Tracking () https://bugzilla.suse.com/show_bug.cgi?id=CVE-2018-7688 -
References (CONFIRM) https://github.com/openSUSE/open-build-service/commit/b15cf19e9e01115f653c76ffdc8f54cd97566553 - Patch () https://github.com/openSUSE/open-build-service/commit/b15cf19e9e01115f653c76ffdc8f54cd97566553 -
References (MLIST) https://lists.opensuse.org/opensuse-buildservice/2018-06/msg00014.html - Mailing List, Release Notes () https://lists.opensuse.org/opensuse-buildservice/2018-06/msg00014.html -

Information

Published : 2018-06-07 13:29

Updated : 2024-11-21 04:12


NVD link : CVE-2018-7688

Mitre link : CVE-2018-7688

CVE.ORG link : CVE-2018-7688


JSON object : View

Products Affected

opensuse

  • open_build_service
CWE
CWE-862

Missing Authorization