First published: Tue Jul 24 2018(Updated: )
openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Open Build Service | <9.2.4 |
https://github.com/openSUSE/open-build-service/commit/f57b660f49f830006766a8d4abc3b4af6e178063
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12466 is a vulnerability in openSUSE openbuildservice before 9.2.4 that allowed authenticated users to delete packages on specific projects with project links.
CVE-2018-12466 has a severity rating of 6.5, which is considered medium.
To fix CVE-2018-12466, it is recommended to update to openSUSE openbuildservice version 9.2.4 or higher.
Yes, you can find references for CVE-2018-12466 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/104958), [Bugzilla](https://bugzilla.suse.com/show_bug.cgi?id=CVE-2018-12466), [GitHub](https://github.com/openSUSE/open-build-service/commit/f57b660f49f830006766a8d4abc3b4af6e178063).
The CWEs associated with CVE-2018-12466 are CWE-732 (Incorrect Permission Assignment for Critical Resource) and CWE-285 (Improper Authorization).