CVE-2017-9268
published 2018-03-01CVE-2017-9268: In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause…
PriorityP427medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
0.61%
45.3th percentile
In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | open-build-service | < open-build-service 2.9.4-1 (bookworm) | open-build-service 2.9.4-1 (bookworm) |
| opensuse | open_build_service | <= 2.8.2 | — |
| suse | open_build_service | >= unspecified < 20170722 git | 20170722 git |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian4.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2mj3-95g6-565f: In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users
ghsa_unreviewed·2022-05-13
CVE-2017-9268 [MEDIUM] CWE-732 GHSA-2mj3-95g6-565f: In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users
In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption).
OSV
CVE-2017-9268: In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users
osv·2018-03-01·CVSS 6.5
CVE-2017-9268 [MEDIUM] CVE-2017-9268: In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users
In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption).
Debian
CVE-2017-9268: open-build-service - In the open build service before 201707022 the wipetrigger and rebuild actions c...
vendor_debian·2017·CVSS 4.4
CVE-2017-9268 [MEDIUM] CVE-2017-9268: open-build-service - In the open build service before 201707022 the wipetrigger and rebuild actions c...
In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption).
Scope: local
bookworm: resolved (fixed in 2.9.4-1)
sid: resolved (fixed in 2.9.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-03-01
Published