First published: Thu Jan 02 2020(Updated: )
obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Obs-server Obs-server | <1.7.7 | |
SUSE Linux Enterprise Server | =11-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2010-3782.
The severity level of CVE-2010-3782 is high.
The affected software includes Obs-server before version 1.7.7 and Suse Linux Enterprise Server version 11-sp1.
An attacker can exploit this vulnerability by logging in using unconfirmed accounts due to a bug in the REST API implementation.
Yes, a fix is available by updating the Obs-server software to version 1.7.7 or later.