CVE-2010-3782: High severity obs-server obs-server vulnerability
Published Jan 2, 2020
·Updated
obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.
Affected Software
2 affected components
obs-server obs-server<1.7.7
SUSE Linux Enterprise Server=11-sp1
Event History
Jan 2, 2020
CVE Published
via MITRE·06:39 PM
Data Sourced
via MITRE·06:39 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2010-3782.
2
What is the severity level of CVE-2010-3782?
The severity level of CVE-2010-3782 is high.
3
What is the affected software?
The affected software includes Obs-server before version 1.7.7 and Suse Linux Enterprise Server version 11-sp1.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by logging in using unconfirmed accounts due to a bug in the REST API implementation.
5
Is there a fix available for this vulnerability?
Yes, a fix is available by updating the Obs-server software to version 1.7.7 or later.