CVE-2014-0594
CSRF protection incorrectly disabled
In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Produtos afetados
openSUSE · Open Build ServiceQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →