Opensuse Open Build Service vulnerabilities
24 known vulnerabilities affecting opensuse/open_build_service.
Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH10MEDIUM11
Vulnerabilities
Page 2 of 2
CVE-2017-9268P4MEDIUMCVSS 6.5≤ 2.8.22018-03-01
CVE-2017-9268 [MEDIUM] CWE-285 CVE-2017-9268: In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong pro
In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption).
nvd
CVE-2018-12475P4MEDIUMCVSS 5.4≥ obs-service-download_files, ≤ 0.6.22020-09-01
CVE-2018-12475 [MEDIUM] CWE-610 CVE-2018-12475: A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-downl
A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows authenticated users to generate HTTP request against internal networks and potentially downloading data that is exposed there. This issue affects: openSUSE Open Build Service .
nvd
CVE-2020-8020P4MEDIUMCVSS 6.1fixed in 2020-05-132020-05-13
CVE-2020-8020 [MEDIUM] CWE-79 CVE-2020-8020: A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service al
A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code to cause XSS. This issue affects: openSUSE open-build-service versions prior to 7cc32c8e2ff7290698e101d9a80a9dc29a5500fb.
nvd
CVE-2020-8031P4MEDIUMCVSS 5.4fixed in 2.10.8≥ Open Build Service, < 2.10.82021-02-11
CVE-2020-8031 [MEDIUM] CWE-79 CVE-2020-8031: A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity. This issue affects: Open Build Service versions prior to 2.10.8.
nvd
← Previous2 / 2