CVE-2018-12466: openbuildservice allowed deleting packages via project links
openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-12466?
CVE-2018-12466 is a vulnerability in openSUSE openbuildservice before 9.2.4 that allowed authenticated users to delete packages on specific projects with project links.
How severe is CVE-2018-12466?
CVE-2018-12466 has a severity rating of 6.5, which is considered medium.
How can I fix CVE-2018-12466?
To fix CVE-2018-12466, it is recommended to update to openSUSE openbuildservice version 9.2.4 or higher.
Are there any references for CVE-2018-12466?
Yes, you can find references for CVE-2018-12466 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/104958), [Bugzilla](https://bugzilla.suse.com/show_bug.cgi?id=CVE-2018-12466), [GitHub](https://github.com/openSUSE/open-build-service/commit/f57b660f49f830006766a8d4abc3b4af6e178063).
What are the CWEs associated with CVE-2018-12466?
The CWEs associated with CVE-2018-12466 are CWE-732 (Incorrect Permission Assignment for Critical Resource) and CWE-285 (Improper Authorization).