cbcvebase.
CVE-2017-9268
published 2018-03-01

CVE-2017-9268: In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause…

PriorityP427medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
0.61%
45.3th percentile
In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption).

Affected

3 ranges
VendorProductVersion rangeFixed in
debianopen-build-service< open-build-service 2.9.4-1 (bookworm)open-build-service 2.9.4-1 (bookworm)
opensuseopen_build_service<= 2.8.2
suseopen_build_service>= unspecified < 20170722 git20170722 git

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian4.4LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.