Marcus Huewe

4 exploits Active since Jun 2018
CVE-2018-12466 WRITEUP MEDIUM WRITEUP
openSUSE openbuildservice <9.2.4 - Privilege Escalation
openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.
CVSS 4.4
CVE-2018-12467 WRITEUP MEDIUM WRITEUP
openSUSE Open Build Service < 2.9.4 - Authenticated Package Deletion via Malicious Request
Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.
CVSS 6.0
CVE-2018-7688 WRITEUP HIGH WRITEUP
openSUSE Open Build Service < 2.9.3 - Authenticated Missing Authorization in Review Handling
A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.
CVSS 7.1
CVE-2018-7689 WRITEUP HIGH WRITEUP
openSUSE Open Build Service < 2.9.3 - Authenticated Missing Authorization in InitializeDevelPackage
Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify packages where they do not have write permissions.
CVSS 7.1