CVE-2018-7689

HIGH

Opensuse Open Build Service < 2.9.3 - Missing Authorization

Title source: rule
STIX 2.1

Description

Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify packages where they do not have write permissions.

Scores

CVSS v3 7.1
EPSS 0.0016
EPSS Percentile 37.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Details

CWE
CWE-862
Status published
Products (1)
opensuse/open_build_service < 2.9.3
Published Jun 07, 2018
Tracked Since Feb 18, 2026