{"api_version":"1","generated_at":"2026-07-23T09:58:25+00:00","cve":"CVE-2018-12474","urls":{"html":"https://cve.report/CVE-2018-12474","api":"https://cve.report/api/cve/CVE-2018-12474.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-12474","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-12474"},"summary":{"title":"CVE-2018-12474","description":"Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: versions prior to 51a17c553b6ae2598820b7a90fd0c11502a49106.","state":"PUBLIC","assigner":"security@microfocus.com","published_at":"2018-10-09 13:29:00","updated_at":"2023-11-07 02:52:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://github.com/openSUSE/obs-service-tar_scm/pull/254","name":"https://github.com/openSUSE/obs-service-tar_scm/pull/254","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"fix regression from 44b3bee by M0ses · Pull Request #254 · openSUSE/obs-service-tar_scm · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1107507","name":"https://bugzilla.suse.com/show_bug.cgi?id=1107507","refsource":"","tags":[],"title":"Bug 1107507 – VUL-0: CVE-2018-12474: obs-service-tar_scm: crafted service parameters allow unexpected behaviour","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-12474","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-12474","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Matthias Gerstner of SUSE","lang":""}],"nvd_cpes":[{"cve_year":"2018","cve_id":"12474","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"tar_scm","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"12474","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"tar_scm","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@microfocus.com","DATE_PUBLIC":"2018-09-26T00:00:00.000Z","ID":"CVE-2018-12474","STATE":"PUBLIC","TITLE":"Crafted service parameters allows to induce unexpected behaviour in obs-service-tar_scm"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Open Build Service","version":{"version_data":[{"affected":"<","version_value":"51a17c553b6ae2598820b7a90fd0c11502a49106"}]}}]},"vendor_name":"openSUSE"}]}},"credit":[{"lang":"eng","value":"Matthias Gerstner of SUSE"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: versions prior to 51a17c553b6ae2598820b7a90fd0c11502a49106."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20: Improper Input Validation"}]}]},"references":{"reference_data":[{"name":"https://github.com/openSUSE/obs-service-tar_scm/pull/254","refsource":"CONFIRM","url":"https://github.com/openSUSE/obs-service-tar_scm/pull/254"},{"name":"https://bugzilla.suse.com/show_bug.cgi?id=1107507","refsource":"CONFIRM","url":"https://bugzilla.suse.com/show_bug.cgi?id=1107507"}]},"source":{"advisory":"https://bugzilla.suse.com/show_bug.cgi?id=1107507","defect":["https://bugzilla.suse.com/show_bug.cgi?id=1107507"],"discovery":"INTERNAL"}},"nvd":{"publishedDate":"2018-10-09 13:29:00","lastModifiedDate":"2023-11-07 02:52:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:opensuse:tar_scm:*:*:*:*:*:*:*:*","versionEndExcluding":"0.9.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"12474","Ordinal":"128992","Title":"CVE-2018-12474","CVE":"CVE-2018-12474","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"12474","Ordinal":"1","NoteData":"Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: versions prior to 51a17c553b6ae2598820b7a90fd0c11502a49106.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"12474","Ordinal":"2","NoteData":"2018-10-09","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"12474","Ordinal":"3","NoteData":"2021-01-06","Type":"Other","Title":"Modified"}]}}}