Lucene search

K
cvelistMicrofocusCVELIST:CVE-2018-12474
HistoryOct 09, 2018 - 1:00 p.m.

CVE-2018-12474 Crafted service parameters allows to induce unexpected behaviour in obs-service-tar_scm

2018-10-0913:00:00
CWE-20
microfocus
www.cve.org
11

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

AI Score

8.6

Confidence

High

EPSS

0.004

Percentile

74.1%

Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: versions prior to 51a17c553b6ae2598820b7a90fd0c11502a49106.

CNA Affected

[
  {
    "product": "Open Build Service",
    "vendor": "openSUSE",
    "versions": [
      {
        "lessThan": "51a17c553b6ae2598820b7a90fd0c11502a49106",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

AI Score

8.6

Confidence

High

EPSS

0.004

Percentile

74.1%

Related for CVELIST:CVE-2018-12474