Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

delete package via link exploit in open buildservice

Disclosure Date: August 01, 2018 (last updated November 08, 2023)
Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.
0
Attacker Value
Unknown

Open Build Service arbitrary package modification

Disclosure Date: June 07, 2018 (last updated November 08, 2023)
Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify packages where they do not have write permissions.
0