CVE-2017-9268
Summary
| CVE | CVE-2017-9268 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-01 20:29:00 UTC |
| Updated | 2023-11-07 02:50:00 UTC |
| Description | In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption). |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Opensuse | Open Build Service | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [webui] fix operating on wrong package build container for wipe, rebu… by adrianschroeter · Pull Request #3267 · openSUSE/open-build-service · GitHub | CONFIRM | github.com | Third Party Advisory |
| Bug 1045519 – VUL-0: CVE-2017-9268: open-build-service: retrigger / wipebinaries hitting the wrong project | CONFIRM | bugzilla.suse.com | Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Adrian Schröter of SUSE
There are currently no legacy QID mappings associated with this CVE.