CVE-2018-12466 MEDIUM

CVE-2018-12466: openbuildservice allowed deleting packages via project links

Vendor Opensuse
Product openbuildservice
Weakness CWE-285
Published August 1, 2018
Last update September 17, 2024

CVSS base score

4.4/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality None
Integrity High

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.

Key dates

02Disclosure timeline

August 1, 2018 CVE published
September 17, 2024 Record updated