PT-2019-4778 · Opensuse+1 · Open Build Service+1

Wolfgang Frisch

·

Published

2019-08-06

·

Updated

2024-06-15

·

CVE-2019-3685

CVSS v2.0

9.0

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions Open Build Service versions prior to 0.165.4
Description The issue is related to errors in certificate authentication. It may allow a remote attacker to bypass existing security restrictions and implement a "man-in-the-middle" attack. The problem arises because Open Build Service before version 0.165.4 did not validate TLS certificates for HTTPS connections with the osc client binary.
Recommendations For versions prior to 0.165.4, update to version 0.165.4 or later to resolve the issue. As a temporary workaround, consider disabling the use of HTTPS connections with the osc client binary until a patch is available. Restrict access to sensitive operations to minimize the risk of exploitation.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01354
CVE-2019-3685
OPENSUSE-SU-2019:1844-1
OPENSUSE-SU-2019_1844-1
OPENSUSE-SU-2024:11133-1
SUSE-SU-2019:2067-1
SUSE-SU-2019_2067-1
SUSE-SU-2022:4351-1

Affected Products

Open Build Service
Suse