CVE-2019-3685: Missing TLS certificate validation for HTTPS connections in osc
Published Nov 5, 2019
·Updated
Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client binary
Affected Software
1 affected component
openSUSE Open Build Service<0.165.4
Remediation
Patch Available
Event History
Nov 5, 2019
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability CVE-2019-3685?
The vulnerability CVE-2019-3685 is related to Open Build Service before version 0.165.4 not validating TLS certificates for HTTPS connections with the osc client binary.
2
How severe is the vulnerability CVE-2019-3685?
The vulnerability CVE-2019-3685 has a severity score of 7.7 (high).
3
What software is affected by the vulnerability CVE-2019-3685?
The openSUSE Open Build Service versions up to and excluding 0.165.4 are affected by the vulnerability CVE-2019-3685.
4
How can I fix the vulnerability CVE-2019-3685?
To fix the vulnerability CVE-2019-3685, you should update Open Build Service to version 0.165.4 or later.
5
Where can I find more information about the vulnerability CVE-2019-3685?
More information about the vulnerability CVE-2019-3685 can be found at https://bugzilla.suse.com/show_bug.cgi?id=1142518.