Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify packages where they do not have write permissions.
References
Link | Resource |
---|---|
https://lists.opensuse.org/opensuse-buildservice/2018-06/msg00014.html | Release Notes |
https://github.com/openSUSE/open-build-service/commit/990ef7cccef6f38fc1d1a1bb22a08e174dcba43b | Patch |
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2018-7689 | Exploit Issue Tracking |
Configurations
Information
Published : 2018-06-07 06:29
Updated : 2019-10-09 16:42
NVD link : CVE-2018-7689
Mitre link : CVE-2018-7689
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
opensuse
- open_build_service