A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.
References
Link | Resource |
---|---|
https://lists.opensuse.org/opensuse-buildservice/2018-06/msg00014.html | Mailing List Release Notes |
https://github.com/openSUSE/open-build-service/commit/b15cf19e9e01115f653c76ffdc8f54cd97566553 | Patch |
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2018-7688 | Issue Tracking |
Configurations
Information
Published : 2018-06-07 06:29
Updated : 2019-10-09 16:42
NVD link : CVE-2018-7688
Mitre link : CVE-2018-7688
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
opensuse
- open_build_service