The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or remove user roles from packages and/or project meta data.
2018-06-08T17:29:00.333
2024-11-21T01:54:08.993
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:N/I:P/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | opensuse | open_build_service | < 2.4.4 | Yes |