CVE-2014-0594
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
Affected (1)
Products: Opensuse: Open Build Service
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.4.6 |
References (4)
Source: security@opentext.com
Source: security@opentext.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.