CVE-2018-12467: delete package via link exploit in open buildservice
Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-12467.
What is the severity of CVE-2018-12467?
The severity of CVE-2018-12467 is medium with a CVSS score of 6.5.
How can authorized users of openbuildservice be affected by CVE-2018-12467?
Authorized users of openbuildservice before version 2.9.4 can be affected by CVE-2018-12467, as they could delete packages by using a malicious request against projects with the OBS:InitializeDevelPackage attribute.
How can I fix CVE-2018-12467?
To fix CVE-2018-12467, it is recommended to update openbuildservice to version 2.9.4 or later.
Are there any references available for CVE-2018-12467?
Yes, you can find references for CVE-2018-12467 at the following links: [Bugzilla - CVE-2018-12467](https://bugzilla.suse.com/show_bug.cgi?id=1100217) and [GitHub - CVE-2018-12467](https://github.com/openSUSE/open-build-service/commit/f57b660f49f830006766a8d4abc3b4af6e178063).