CVE-2018-7688: Open Build Service accepts arbitrary reviews
Published Jun 7, 2018
·Updated
A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.
Affected Software
1 affected component
openSUSE Open Build Service<2.9.3
Remediation
Event History
Jun 7, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-7688.
2
What is the severity of CVE-2018-7688?
The severity of CVE-2018-7688 is high.
3
What is the affected software for CVE-2018-7688?
The affected software for CVE-2018-7688 is openSUSE Open Build Service up to version 2.9.3.
4
What is the CWE category for CVE-2018-7688?
The CWE category for CVE-2018-7688 is CWE-862.
5
How can I fix CVE-2018-7688?
To fix CVE-2018-7688, you should update to openSUSE Open Build Service version 2.9.3 or newer.