CVE-2017-5188: OBS worker VM escape via relative symbolic links
Published Mar 1, 2018
·Updated
The bsworker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source directory during build, allowing leakage of private information.
Affected Software
1 affected component
openSUSE Open Build Service<=2.7.3
Remediation
Event History
Mar 1, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2017-5188.
2
What is the title of this vulnerability?
The title of this vulnerability is 'The bs_worker code in open build service before 20170320 followed relative symlinks allowing reading…'
3
What is the severity of CVE-2017-5188?
The severity of CVE-2017-5188 is high, with a severity value of 7.5.
4
Which software is affected by CVE-2017-5188?
The openSUSE Open Build Service version up to and including 2.7.3 is affected by CVE-2017-5188.
5
How can the vulnerability be fixed?
To fix the vulnerability, update the openSUSE Open Build Service to a version later than 20170320.