login-proxy sends password to attacker-provided domain
Vulnerability Description
A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects: openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-36777
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Bernhard Wiedemann, Victor Pereira and Marcus Rueckert of SUSE
More from openSUSE
View All →Affected Vendor
openSUSE
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.