VendorsopenSUSEopen_build_serviceall versions
Vulnerabilities

openSUSE Open Build Service (OBS)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2014-0593
sed command injection
Published 2018-06-08 · Modified
10.0EPSS 0.019
CVE-2011-4183
open build service allows anyone to upload rpms
Published 2018-06-13 · Modified
9.8EPSS 0.016
CVE-2022-21949
Multiple XXE vulnerabilities in OBS
Published 2022-05-03 · Modified
9.0EPSS 0.019
CVE-2011-3178
openbuildservice webui code injection
Published 2018-03-20 · Modified
8.8EPSS 0.013
CVE-2013-3703
No write permission check in change_role command
Published 2018-06-08 · Modified
8.8EPSS 0.009
CVE-2021-36777
login-proxy sends password to attacker-provided domain
Published 2022-03-09 · Modified
8.8EPSS 0.009
CVE-2014-0594
CSRF protection incorrectly disabled
Published 2018-06-08 · Modified
8.8EPSS 0.008
CVE-2019-3685
Missing TLS certificate validation for HTTPS connections in osc
Published 2019-11-05 · Modified
7.7EPSS 0.007
CVE-2018-12473
path traversal in obs-service-tar_scm
Published 2018-10-02 · Modified
7.5EPSS 0.018
CVE-2018-12479
Request controller allows to create requests with arbitrary request IDs
Published 2018-10-09 · Modified
7.5EPSS 0.017
CVE-2011-4181
open build service information leak via unauthorized source access
Published 2018-06-11 · Modified
7.5EPSS 0.014
CVE-2017-5188
OBS worker VM escape via relative symbolic links
Published 2018-03-01 · Modified
7.5EPSS 0.011
CVE-2018-7689
Open Build Service arbitrary package modification
Published 2018-06-07 · Modified
7.1EPSS 0.012
CVE-2018-7688
Open Build Service accepts arbitrary reviews
Published 2018-06-07 · Modified
7.1EPSS 0.011
CVE-2018-12478
obs-service-replace_using_package_version allows to specify arbitrary input files
Published 2018-10-09 · Modified
6.5EPSS 0.015
CVE-2020-8020
Persistent XSS in markdown parser used by obs-server
Published 2020-05-13 · Modified
6.5EPSS 0.009
CVE-2018-12466
openbuildservice allowed deleting packages via project links
Published 2018-08-01 · Modified
6.5EPSS 0.008
CVE-2018-12467
delete package via link exploit in open buildservice
Published 2018-08-01 · Modified
6.5EPSS 0.006
CVE-2018-12475
obs-service-download_files allows downloading from localhost or intranet hosts
Published 2020-09-01 · Modified
6.5EPSS 0.006
CVE-2017-9268
open-build-service retrigger / wipebinaries hitting the wrong project bypassing access permissions
Published 2018-03-01 · Modified
6.5EPSS 0.006
CVE-2020-8031
obs: Stored XSS
Published 2021-02-11 · Modified
6.3EPSS 0.007
CVE-2020-8021
unauthorized read access to files where sourceaccess is disabled via a crafted _service file in Open Build Service
Published 2020-05-19 · Modified
5.3EPSS 0.013