CVE-2018-7689

Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify packages where they do not have write permissions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opensuse:open_build_service:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:01

Type Values Removed Values Added
References (CONFIRM) https://github.com/openSUSE/open-build-service/commit/990ef7cccef6f38fc1d1a1bb22a08e174dcba43b - Patch () https://github.com/openSUSE/open-build-service/commit/990ef7cccef6f38fc1d1a1bb22a08e174dcba43b -
References (CONFIRM) https://bugzilla.suse.com/show_bug.cgi?id=CVE-2018-7689 - Exploit, Issue Tracking () https://bugzilla.suse.com/show_bug.cgi?id=CVE-2018-7689 -
References (MLIST) https://lists.opensuse.org/opensuse-buildservice/2018-06/msg00014.html - Release Notes () https://lists.opensuse.org/opensuse-buildservice/2018-06/msg00014.html -

Information

Published : 2018-06-07 13:29

Updated : 2024-02-28 16:25


NVD link : CVE-2018-7689

Mitre link : CVE-2018-7689

CVE.ORG link : CVE-2018-7689


JSON object : View

Products Affected

opensuse

  • open_build_service
CWE
CWE-862

Missing Authorization