CVE-2020-8021: unauthorized read access to files where sourceaccess is disabled via a crafted _service file in Open Build Service
a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled This issue affects: Open Build Service versions prior to 2.10.5.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-8021?
CVE-2020-8021 is an Improper Access Control vulnerability in Open Build Service that allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled.
Which versions of Open Build Service are affected by CVE-2020-8021?
Open Build Service versions prior to 2.10.5 are affected by CVE-2020-8021.
How severe is CVE-2020-8021?
CVE-2020-8021 has a severity rating of 5.3 out of 10, which is considered medium.
How can I fix CVE-2020-8021?
To fix CVE-2020-8021, upgrade to Open Build Service version 2.10.5 or later.
Where can I find more information about CVE-2020-8021?
You can find more information about CVE-2020-8021 at the following references: [Bugzilla](https://bugzilla.suse.com/show_bug.cgi?id=1171649) and [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2021/02/msg00006.html).