First published: Tue Jul 24 2018(Updated: )
Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Open Build Service | <2.9.4 |
https://github.com/openSUSE/open-build-service/commit/f57b660f49f830006766a8d4abc3b4af6e178063
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-12467.
The severity of CVE-2018-12467 is medium with a CVSS score of 6.5.
Authorized users of openbuildservice before version 2.9.4 can be affected by CVE-2018-12467, as they could delete packages by using a malicious request against projects with the OBS:InitializeDevelPackage attribute.
To fix CVE-2018-12467, it is recommended to update openbuildservice to version 2.9.4 or later.
Yes, you can find references for CVE-2018-12467 at the following links: [Bugzilla - CVE-2018-12467](https://bugzilla.suse.com/show_bug.cgi?id=1100217) and [GitHub - CVE-2018-12467](https://github.com/openSUSE/open-build-service/commit/f57b660f49f830006766a8d4abc3b4af6e178063).