CVE-2018-7689Missing Authorization in Open Build Service

Severity
6.5MEDIUMNVD
CNA7.1
EPSS
0.2%
top 62.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 7
Latest updateMay 13

Description

Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify packages where they do not have write permissions.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5opensuse/open_build_serviceunspecified2.9.3

🔴Vulnerability Details

3
GHSA
GHSA-mcfv-wm6f-9ch2: Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 22022-05-13
OSV
CVE-2018-7689: Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 22018-06-07
CVEList
Open Build Service arbitrary package modification2018-06-07

📋Vendor Advisories

1
Debian
CVE-2018-7689: open-build-service - Lack of permission checks in the InitializeDevelPackage function in openSUSE Ope...2018
CVE-2018-7689 — Missing Authorization | cvebase