cbcvebase.
CVE-2010-3782
published 2020-01-02

CVE-2010-3782: obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianopen-build-service
obs-serverobs-server< 1.7.71.7.7
suselinux_enterprise_server