Vulnerabilities (CVE)

Filtered by vendor Opensuse Subscribe
Filtered by product Open Build Service
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-0593 1 Opensuse 1 Open Build Service 2019-10-09 10.0 HIGH 9.8 CRITICAL
The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). In versions prior to 0.5.3-1.1 this script did not properly sanitize the input provided by the user, allowing for code execution on the executing server.
CVE-2011-4183 1 Opensuse 1 Open Build Service 2019-10-09 7.5 HIGH 9.8 CRITICAL
A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16.