In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to execute shellcode.
2018-03-20T18:29:00.257
2024-11-21T01:29:54.850
Modified
CVSSv3.0: 8.1 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | opensuse | open_build_service | < 2.3.0 | Yes |