A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows authenticated users to generate HTTP request against internal networks and potentially downloading data that is exposed there. This issue affects: openSUSE Open Build Service .
References
Link | Resource |
---|---|
https://bugzilla.suse.com/show_bug.cgi?id=1107821 | Issue Tracking Vendor Advisory |
Configurations
Information
Published : 2020-09-01 05:15
Updated : 2020-09-10 09:39
NVD link : CVE-2018-12475
Mitre link : CVE-2018-12475
JSON object : View
CWE
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
Products Affected
opensuse
- open_build_service