A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.
References
| Link | Resource |
|---|---|
| https://lists.opensuse.org/opensuse-buildservice/2018-06/msg00014.html | Mailing List Release Notes |
| https://github.com/openSUSE/open-build-service/commit/b15cf19e9e01115f653c76ffdc8f54cd97566553 | Patch |
| https://bugzilla.suse.com/show_bug.cgi?id=CVE-2018-7688 | Issue Tracking |
Configurations
Information
Published : 2018-06-07 13:29
Updated : 2019-10-09 23:42
NVD link : CVE-2018-7688
Mitre link : CVE-2018-7688
JSON object : View
Products Affected
opensuse
- open_build_service
CWE
CWE-862
Missing Authorization
