Open Build Service accepts arbitrary reviews
Vulnerability Description
A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-7688
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Marcus Hüwe
References
More from openSUSE
View All →Affected Vendor
openSUSE
View all reports →