The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or remove user roles from packages and/or project meta data.
References
Configurations
History
No history.
Information
Published : 2018-06-08 17:29
Updated : 2023-11-07 02:16
NVD link : CVE-2013-3703
Mitre link : CVE-2013-3703
CVE.ORG link : CVE-2013-3703
JSON object : View
Products Affected
opensuse
- open_build_service