{"api_version":"1","generated_at":"2026-07-23T01:53:12+00:00","cve":"CVE-2011-4181","urls":{"html":"https://cve.report/CVE-2011-4181","api":"https://cve.report/api/cve/CVE-2011-4181.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-4181","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-4181"},"summary":{"title":"CVE-2011-4181","description":"A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases are SUSE open build service up to and including version 2.1.15 (for 2.1) and before version 2.3.","state":"PUBLIC","assigner":"security@microfocus.com","published_at":"2018-06-11 15:29:00","updated_at":"2023-11-07 02:09:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=734003","name":"https://bugzilla.suse.com/show_bug.cgi?id=734003","refsource":"CONFIRM","tags":["Issue Tracking"],"title":"Bug 734003 – VUL-0: OBS information leak via unauthorized source access","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/openSUSE/open-build-service/commit/5281e4bff9df31f1f91e22a0d1e9086b93b23d7e","name":"https://github.com/openSUSE/open-build-service/commit/5281e4bff9df31f1f91e22a0d1e9086b93b23d7e","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"[api] support binary package upload for the admin · openSUSE/open-build-service@5281e4b · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-4181","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4181","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"4181","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opensuse","cpe5":"open_build_service","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4181","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opensuse","cpe5":"open_build_service","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@microfocus.com","DATE_PUBLIC":"2011-12-06","ID":"CVE-2011-4181","STATE":"PUBLIC","TITLE":"open build service information leak via unauthorized source access"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"open build service","version":{"version_data":[{"affected":"<=","version_value":"2.1.15"},{"affected":"<","version_value":"2.3"}]}}]},"vendor_name":"SUSE"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases are SUSE open build service up to and including version 2.1.15 (for 2.1) and before version 2.3."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-284"}]}]},"references":{"reference_data":[{"name":"https://github.com/openSUSE/open-build-service/commit/5281e4bff9df31f1f91e22a0d1e9086b93b23d7e","refsource":"CONFIRM","url":"https://github.com/openSUSE/open-build-service/commit/5281e4bff9df31f1f91e22a0d1e9086b93b23d7e"},{"name":"https://bugzilla.suse.com/show_bug.cgi?id=734003","refsource":"CONFIRM","url":"https://bugzilla.suse.com/show_bug.cgi?id=734003"}]},"source":{"defect":["734003"],"discovery":"INTERNAL"}},"nvd":{"publishedDate":"2018-06-11 15:29:00","lastModifiedDate":"2023-11-07 02:09:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:opensuse:open_build_service:*:*:*:*:*:*:*:*","versionStartIncluding":"2.1.0","versionEndExcluding":"2.1.16","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"4181","Ordinal":"51588","Title":"CVE-2011-4181","CVE":"CVE-2011-4181","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"4181","Ordinal":"1","NoteData":"A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases are SUSE open build service up to and including version 2.1.15 (for 2.1) and before version 2.3.","Type":"Description","Title":null},{"CveYear":"2011","CveId":"4181","Ordinal":"2","NoteData":"2018-06-11","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"4181","Ordinal":"3","NoteData":"2021-01-06","Type":"Other","Title":"Modified"}]}}}