9
CVSSv2

CVE-2022-21949

Published: 03/05/2022 Updated: 10/05/2022
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 802
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote malicious users to reference external entities in certain operations. This can be used to gain information from the server that can be abused to escalate to Admin privileges on OBS. This issue affects: SUSE Open Build Service Open Build Service versions before 2.10.13.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse open build service

Vendor Advisories

Debian Bug report logs - #1010667 ruby-xmlhash: CVE-2022-21949 - Improper Restriction of XML External Entity Reference Package: src:ruby-xmlhash; Maintainer for src:ruby-xmlhash is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Neil Williams <codehelp@debianorg> Dat ...