CVE-2018-12478: obs-service-replace_using_package_version allows to specify arbitrary input files
Published Oct 9, 2018
·Updated
A Improper Input Validation vulnerability in Open Build Service allows remote attackers to extract files from the system where the service runs. Affected releases are openSUSE Open Build Service: status of is unknown.
Affected Software
1 affected component
openSUSE Open Build Service
Event History
Oct 9, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-12478.
2
What is the severity level of CVE-2018-12478?
The severity level of CVE-2018-12478 is medium.
3
How does the vulnerability CVE-2018-12478 exploit the system?
CVE-2018-12478 allows remote attackers to extract files from the system where the Open Build Service runs.
4
Which software is affected by CVE-2018-12478?
The affected software is openSUSE Open Build Service.
5
Is there a known fix for CVE-2018-12478?
There is no information about the status or fix of CVE-2018-12478.