First published: Tue Nov 05 2019(Updated: )
Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client binary
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Open Build Service | <0.165.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability CVE-2019-3685 is related to Open Build Service before version 0.165.4 not validating TLS certificates for HTTPS connections with the osc client binary.
The vulnerability CVE-2019-3685 has a severity score of 7.7 (high).
The openSUSE Open Build Service versions up to and excluding 0.165.4 are affected by the vulnerability CVE-2019-3685.
To fix the vulnerability CVE-2019-3685, you should update Open Build Service to version 0.165.4 or later.
More information about the vulnerability CVE-2019-3685 can be found at https://bugzilla.suse.com/show_bug.cgi?id=1142518.