Opensuse · Opensuse Open Build Service · CVE-2018-7689
**Name of the Vulnerable Software and Affected Versions**
openSUSE Open Build Service versions prior to 2.9.3
**Description**
The issue is related to a lack of permission checks in the InitializeDevelPackage function, allowing authenticated users to modify packages without having the necessary write permissions.
**Recommendations**
For versions prior to 2.9.3, update to version 2.9.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the InitializeDevelPackage function to minimize the risk of exploitation.