First published: Wed Mar 26 2014(Updated: )
In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Open Build Service | <2.4.6 |
https://github.com/openSUSE/open-build-service/commit/2188c059b67b82171d0e28ef59f77e62d22a09d8
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2014-0594.
The severity of CVE-2014-0594 is high with a severity value of 8.8.
CVE-2014-0594 is a vulnerability in the Open Build Service (OBS) before version 2.4.6 where the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
The affected software for CVE-2014-0594 is openSUSE Open Build Service before version 2.4.6.
To fix CVE-2014-0594, it is recommended to update the Open Build Service (OBS) to version 2.4.6 or later.