Vulnerability Description
The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or remove user roles from packages and/or project meta data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opensuse | Open Build Service | >= 2.4.0, < 2.4.4 |
Related Weaknesses (CWE)
References
- https://bugzilla.suse.com/show_bug.cgi?id=828256
- https://github.com/openSUSE/open-build-service/commit/06ad7fdbdd7eb2fef8947d14c4
- https://bugzilla.suse.com/show_bug.cgi?id=828256
- https://github.com/openSUSE/open-build-service/commit/06ad7fdbdd7eb2fef8947d14c4
FAQ
What is CVE-2013-3703?
CVE-2013-3703 is a vulnerability with a CVSS score of 8.8 (HIGH). The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or remove user roles from packages and/or project met...
How severe is CVE-2013-3703?
CVE-2013-3703 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3703?
Check the references section above for vendor advisories and patch information. Affected products include: Opensuse Open Build Service.