Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify packages where they do not have write permissions.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2018-19405 | Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify packages where they do not have write permissions. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: microfocus
Published:
Updated: 2024-09-16T22:40:22.144Z
Reserved: 2018-03-05T00:00:00
Link: CVE-2018-7689

No data.

Status : Modified
Published: 2018-06-07T13:29:00.337
Modified: 2024-11-21T04:12:32.647
Link: CVE-2018-7689

No data.

No data.