Lucene search

K
cveMicrofocusCVE-2014-0593
HistoryJun 08, 2018 - 5:29 p.m.

CVE-2014-0593

2018-06-0817:29:00
CWE-78
CWE-20
microfocus
web.nvd.nist.gov
22
cve-2014-0593
open build service
obs
source validator
input sanitation
code execution
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.008

Percentile

82.1%

The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). In versions prior to 0.5.3-1.1 this script did not properly sanitize the input provided by the user, allowing for code execution on the executing server.

Affected configurations

Nvd
Node
opensuseopen_build_serviceRange0.5.31.1
VendorProductVersionCPE
opensuseopen_build_service*cpe:2.3:o:opensuse:open_build_service:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "obs-service-set_version",
    "vendor": "openSUSE",
    "versions": [
      {
        "lessThan": "0.5.3-1.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.008

Percentile

82.1%

Related for CVE-2014-0593