Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
opensuse open build service - vulnerabilities and exploits
(subscribe to this query)
4
CVSSv2
CVE-2018-7689
Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service prior to 2.9.3 allowed authenticated users to modify packages where they do not have write permissions.
Opensuse Open Build Service
6.8
CVSSv2
CVE-2014-0594
In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
Opensuse Open Build Service
4.3
CVSSv2
CVE-2018-12478
A Improper Input Validation vulnerability in Open Build Service allows remote malicious users to extract files from the system where the service runs. Affected releases are openSUSE Open Build Service: status of is unknown.
Opensuse Open Build Service -
5
CVSSv2
CVE-2011-4181
A vulnerability in open build service allows remote malicious users to gain access to source files even though source access is disabled. Affected releases are SUSE open build service up to and including version 2.1.15 (for 2.1) and before version 2.3.
Opensuse Open Build Service
7.5
CVSSv2
CVE-2011-4183
A vulnerability in open build service allows remote malicious users to upload arbitrary RPM files. Affected releases are SUSE open build service before 2.1.16.
Opensuse Open Build Service
6.8
CVSSv2
CVE-2019-3685
Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client binary
Opensuse Open Build Service
4
CVSSv2
CVE-2017-9268
In the open build service prior to 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption).
Opensuse Open Build Service
5.5
CVSSv2
CVE-2018-12466
openSUSE openbuildservice prior to 9.2.4 allowed authenticated users to delete packages on specific projects with project links.
Opensuse Open Build Service
6.5
CVSSv2
CVE-2011-3178
In the web ui of the openbuildservice prior to 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized malicious users to execute shellcode.
Opensuse Open Build Service
6.8
CVSSv2
CVE-2021-36777
A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed malicious users to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects:...
Opensuse Open Build Service
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »