Описание
Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support, was needs-triage |
cosmic | ignored | end of life |
devel | needs-triage | |
disco | not-affected | 2.9.4-1 |
eoan | not-affected | 2.9.4-2 |
esm-apps/bionic | needs-triage | |
esm-apps/noble | needs-triage | |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | DNE | |
focal | DNE |
Показывать по
EPSS
5.5 Medium
CVSS2
6 Medium
CVSS3
Связанные уязвимости
Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.
Authorized users of the openbuildservice before 2.9.4 could delete pac ...
Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.
EPSS
5.5 Medium
CVSS2
6 Medium
CVSS3