CVE-2018-7689

MEDIUM6.5EPSS 0.17%
Published: 6/7/2018Modified: 4/28/2026
Also known as:DEBIAN-CVE-2018-7689

Description

Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify packages where they do not have write permissions.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

References (1)