ZeroHour

CVE-2018-7688

CVSS 3.0
6.5 medium
EPSS
1%p64
Published
()
Modified
Description

A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.

Vendors
opensuse
Products
open build service
Weakness
CWE-862
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.