First published: Tue May 19 2020(Updated: )
a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled This issue affects: Open Build Service versions prior to 2.10.5.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Open Build Service | <2.10.5 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8021 is an Improper Access Control vulnerability in Open Build Service that allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled.
Open Build Service versions prior to 2.10.5 are affected by CVE-2020-8021.
CVE-2020-8021 has a severity rating of 5.3 out of 10, which is considered medium.
To fix CVE-2020-8021, upgrade to Open Build Service version 2.10.5 or later.
You can find more information about CVE-2020-8021 at the following references: [Bugzilla](https://bugzilla.suse.com/show_bug.cgi?id=1171649) and [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2021/02/msg00006.html).