← back
CVE-2018-7688

Open Build Service accepts arbitrary reviews

CVSS 7.1 HIGHEPSS 1.1%CWE-862
A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →