Lucene search

K
cvelistMicrofocusCVELIST:CVE-2017-9268
HistoryJun 22, 2017 - 12:00 a.m.

CVE-2017-9268 open-build-service retrigger / wipebinaries hitting the wrong project bypassing access permissions

2017-06-2200:00:00
CWE-285
microfocus
www.cve.org
1

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

0.001 Low

EPSS

Percentile

36.5%

In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption).

CNA Affected

[
  {
    "product": "open build service",
    "vendor": "SUSE",
    "versions": [
      {
        "lessThan": "20170722 git",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

0.001 Low

EPSS

Percentile

36.5%

Related for CVELIST:CVE-2017-9268