CVE-2018-12479: Request controller allows to create requests with arbitrary request IDs
Published Oct 9, 2018
·Updated
A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS by specifying crafted request IDs. Affected releases are openSUSE Open Build Service: versions prior to 01b015ca2a320afc4fae823465d1e72da8bd60df.
Affected Software
1 affected component
openSUSE Open Build Service<=2.9.4
Event History
Oct 9, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2018-12479.
2
What is the title of this vulnerability?
The title of this vulnerability is 'A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS'.
3
What is the severity of CVE-2018-12479?
The severity of CVE-2018-12479 is high with a severity value of 7.5.
4
Which software is affected by CVE-2018-12479?
openSUSE Open Build Service versions prior to 2.9.4 are affected by CVE-2018-12479.
5
How can remote attackers exploit CVE-2018-12479?
Remote attackers can exploit CVE-2018-12479 by specifying crafted request IDs, potentially causing a Denial of Service (DoS) attack.