Vulnerability Description
A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects: openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opensuse | Open Build Service | < 2021-10-08 |
Related Weaknesses (CWE)
References
- https://bugzilla.suse.com/show_bug.cgi?id=1191209ExploitIssue TrackingPatch
- https://bugzilla.suse.com/show_bug.cgi?id=1191209ExploitIssue TrackingPatch
FAQ
What is CVE-2021-36777?
CVE-2021-36777 is a vulnerability with a CVSS score of 8.1 (HIGH). A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the c...
How severe is CVE-2021-36777?
CVE-2021-36777 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-36777?
Check the references section above for vendor advisories and patch information. Affected products include: Opensuse Open Build Service.