CVE-2014-0594: CSRF protection incorrectly disabled
Published Jun 8, 2018
·Updated
In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
Affected Software
1 affected component
openSUSE Open Build Service<2.4.6
Remediation
Patch Available
Event History
Jun 8, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2014-0594.
2
What is the severity of CVE-2014-0594?
The severity of CVE-2014-0594 is high with a severity value of 8.8.
3
What is the description of CVE-2014-0594?
CVE-2014-0594 is a vulnerability in the Open Build Service (OBS) before version 2.4.6 where the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
4
What is the affected software for CVE-2014-0594?
The affected software for CVE-2014-0594 is openSUSE Open Build Service before version 2.4.6.
5
How can I fix CVE-2014-0594?
To fix CVE-2014-0594, it is recommended to update the Open Build Service (OBS) to version 2.4.6 or later.