Vulnerabilities (CVE)

Filtered by vendor Opensuse Subscribe
Filtered by product Open Build Service
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-21949 1 Opensuse 1 Open Build Service 2022-05-10 9.0 HIGH 8.8 HIGH
A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote attackers to reference external entities in certain operations. This can be used to gain information from the server that can be abused to escalate to Admin privileges on OBS. This issue affects: SUSE Open Build Service Open Build Service versions prior to 2.10.13.
CVE-2019-3685 1 Opensuse 1 Open Build Service 2019-11-08 6.8 MEDIUM 7.7 HIGH
Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client binary
CVE-2018-12473 1 Opensuse 1 Open Build Service 2019-10-09 5.0 MEDIUM 7.5 HIGH
A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause access files not in the current build. On the server itself this is prevented by confining the worker via KVM. Affected releases are openSUSE Open Build Service: versions prior to 70d1aa4cc4d7b940180553a63805c22fc62e2cf0.
CVE-2018-12479 1 Opensuse 1 Open Build Service 2019-10-09 5.0 MEDIUM 7.5 HIGH
A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS by specifying crafted request IDs. Affected releases are openSUSE Open Build Service: versions prior to 01b015ca2a320afc4fae823465d1e72da8bd60df.
CVE-2017-5188 1 Opensuse 1 Open Build Service 2019-10-09 5.0 MEDIUM 7.5 HIGH
The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source directory during build, allowing leakage of private information.
CVE-2014-0594 1 Opensuse 1 Open Build Service 2019-10-09 6.8 MEDIUM 8.8 HIGH
In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
CVE-2011-3178 1 Opensuse 1 Open Build Service 2019-10-09 6.5 MEDIUM 8.8 HIGH
In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to execute shellcode.
CVE-2011-4181 1 Opensuse 1 Open Build Service 2019-10-09 5.0 MEDIUM 7.5 HIGH
A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases are SUSE open build service up to and including version 2.1.15 (for 2.1) and before version 2.3.