First published: Sun Apr 10 2011(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the login page in the webui component in SUSE openSUSE Build Service (OBS) before 2.1.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Opensuse Build Service | =2.0.103 | |
Novell Opensuse Build Service | =2.0 | |
Novell Opensuse Build Service | =2.1.4 | |
Novell Opensuse Build Service | =2.0.106 | |
Novell Opensuse Build Service | =2.0.16 | |
Novell Opensuse Build Service | =2.0.2 | |
Novell Opensuse Build Service | =1.7 | |
Novell Opensuse Build Service | =2.0.7 | |
Novell Opensuse Build Service | =1.0 | |
Novell Opensuse Build Service | <=2.1.5.1 | |
Novell Opensuse Build Service | =1.7.5 | |
Novell Opensuse Build Service | =2.0.0 | |
Novell Opensuse Build Service | =1.7.6 | |
Novell Opensuse Build Service | =1.9.90 | |
Novell Opensuse Build Service | =2.1.3 | |
Novell Opensuse Build Service | =1.9.91 | |
Novell Opensuse Build Service | =1.7.0 | |
Novell Opensuse Build Service | =1.5 | |
Novell Opensuse Build Service | =2.0.8 | |
Novell Opensuse Build Service | =2.0.5 | |
Novell Opensuse Build Service | =2.1.0 | |
Novell Opensuse Build Service | =2.1.1 | |
Novell Opensuse Build Service | =1.9.92 | |
Novell Opensuse Build Service | =2.0.1 | |
Novell Opensuse Build Service | =1.7.7 | |
Novell Opensuse Build Service | =1.7.4 | |
Novell Opensuse Build Service | =2.1.5 | |
Novell Opensuse Build Service | =2.0.104 | |
Novell Opensuse Build Service | =2.0.6 | |
Novell Opensuse Build Service | =1.7.2 | |
Novell Opensuse Build Service | =2.0.4 | |
Novell Opensuse Build Service | =2.1.2 | |
Novell Opensuse Build Service | =2.0.3 | |
Novell Opensuse Build Service | =1.7.3 | |
Novell Opensuse Build Service | =1.6 | |
Novell Opensuse Build Service | =1.8 | |
Novell Opensuse Build Service | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0462 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2011-0462, upgrade to SUSE openSUSE Build Service version 2.1.6 or later.
CVE-2011-0462 allows remote attackers to perform cross-site scripting attacks that can lead to information theft or session hijacking.
CVE-2011-0462 affects the webui component of SUSE openSUSE Build Service.
Versions of SUSE openSUSE Build Service prior to 2.1.6, including 1.0 to 2.1.5.1, are vulnerable to CVE-2011-0462.