CVE-2018-7688

HIGH

openSUSE Open Build Service < 2.9.3 - Authenticated Missing Authorization in Review Handling

Title source: llm
STIX 2.1

Description

A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.

Scores

CVSS v3 7.1
EPSS 0.0110
EPSS Percentile 61.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Details

CWE
CWE-862
Status published
Products (1)
opensuse/open_build_service < 2.9.3
Published Jun 07, 2018
Tracked Since Feb 18, 2026