Marcus Huewe

4 exploits Active since Jun 2018
CVE-2018-12466 WRITEUP MEDIUM WRITEUP
openSUSE openbuildservice <9.2.4 - Privilege Escalation
openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.
CVSS 4.4
CVE-2018-12467 WRITEUP MEDIUM WRITEUP
OBS <2.9.4 - Privilege Escalation
Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.
CVSS 6.0
CVE-2018-7688 WRITEUP HIGH WRITEUP
Opensuse Open Build Service < 2.9.3 - Missing Authorization
A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.
CVSS 7.1
CVE-2018-7689 WRITEUP HIGH WRITEUP
Opensuse Open Build Service < 2.9.3 - Missing Authorization
Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify packages where they do not have write permissions.
CVSS 7.1