Vulnerability Description
In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opensuse | Open Build Service | < 2.4.6 |
Related Weaknesses (CWE)
References
- https://bugzilla.suse.com/show_bug.cgi?id=870606
- https://github.com/openSUSE/open-build-service/commit/2188c059b67b82171d0e28ef59
- https://bugzilla.suse.com/show_bug.cgi?id=870606
- https://github.com/openSUSE/open-build-service/commit/2188c059b67b82171d0e28ef59
FAQ
What is CVE-2014-0594?
CVE-2014-0594 is a vulnerability with a CVSS score of 8.8 (HIGH). In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
How severe is CVE-2014-0594?
CVE-2014-0594 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0594?
Check the references section above for vendor advisories and patch information. Affected products include: Opensuse Open Build Service.