Required CVE Record Information
Description
openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
4.4 | MEDIUM | 3.0 | CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N |
Credits
- Marcus Hüwe
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- securityfocus.com: 104958 vdb-entryx_transferred
- https://github.com/openSUSE/open-build-service/commit/f57b660f49f830006766a8d4abc3b4af6e178063 x_transferred
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2018-12466 x_transferred