First published: Thu Jun 07 2018(Updated: )
A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Open Build Service | <2.9.3 |
https://github.com/openSUSE/open-build-service/commit/b15cf19e9e01115f653c76ffdc8f54cd97566553
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-7688.
The severity of CVE-2018-7688 is high.
The affected software for CVE-2018-7688 is openSUSE Open Build Service up to version 2.9.3.
The CWE category for CVE-2018-7688 is CWE-862.
To fix CVE-2018-7688, you should update to openSUSE Open Build Service version 2.9.3 or newer.