Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.
2018-08-01T15:29:00.330
2024-11-21T03:45:16.490
Modified
CVSSv3.0: 6.0 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:P/A:P
8.0
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | opensuse | open_build_service | < 2.9.4 | Yes |