Back to Database
Status published
High
CVE-2014-0594
CSRF protection incorrectly disabled
Vulnerability Description
In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-0594
Credits & Attribution
No credits recorded in the NVD database.
References
More from openSUSE
View All →CVE-2025-53881
SUSE-specific logrotate configuration allows escalation from mail user/group to root
Medium
6.9
CVE-2025-46810
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging...
High
8.5
CVE-2024-49506
Fixed temporary file path in aeon-checks allows fixing of disk encryption key
High
7.3
CVE-2024-49505
XSS vulnerability found in OpenSuse MirrorCache
Medium
5.3
CVE-2023-32184
A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome...
High
7.8
Affected Vendor
openSUSE
View all reports →Affected Software
Open Build Service
Vulnerable Versions:
unspecified
Timeline
Official Publish:
June 8th, 2018
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H