Severity
8.8HIGH
EPSS
0.3%
top 45.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20
Latest updateMay 13

Description

In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to execute shellcode.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

CVEListV5opensuse/openbuildserviceunspecified2.3.0

🔴Vulnerability Details

2
GHSA
GHSA-p99p-mq58-p5hh: In the web ui of the openbuildservice before 22022-05-13
CVEList
openbuildservice webui code injection2018-03-20

📋Vendor Advisories

1
Debian
CVE-2011-3178: open-build-service - In the web ui of the openbuildservice before 2.3.0 a code injection of the proje...2011
CVE-2011-3178 (HIGH CVSS 8.8) | In the web ui of the openbuildservi | cvebase.io