PT-2022-15198 · Suse+1 · Opensuse Open Build Service+1

Victor Pereira

·

Published

2022-05-03

·

Updated

2022-05-25

·

CVE-2022-21949

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SUSE Open Build Service versions prior to 2.10.13
Description A vulnerability in SUSE Open Build Service allows remote attackers to reference external entities in certain operations, potentially gaining information from the server that can be abused to escalate to Admin privileges on OBS.
Recommendations For versions prior to 2.10.13, update to version 2.10.13 or later to resolve the issue. As a temporary workaround, consider restricting access to certain operations that may be vulnerable to XML External Entity Reference attacks until a patch is applied.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-21949
OESA-2022-1674

Affected Products

Debian
Opensuse Open Build Service