PT-2022-15198 · Suse+1 · Opensuse Open Build Service+1
Victor Pereira
·
Published
2022-05-03
·
Updated
2022-05-25
·
CVE-2022-21949
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SUSE Open Build Service versions prior to 2.10.13
Description
A vulnerability in SUSE Open Build Service allows remote attackers to reference external entities in certain operations, potentially gaining information from the server that can be abused to escalate to Admin privileges on OBS.
Recommendations
For versions prior to 2.10.13, update to version 2.10.13 or later to resolve the issue. As a temporary workaround, consider restricting access to certain operations that may be vulnerable to XML External Entity Reference attacks until a patch is applied.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Opensuse Open Build Service