Vulnerability Name: | CVE-2011-4181 (CCN-148087) | ||||||||||||||||||||||||
Assigned: | 2011-12-01 | ||||||||||||||||||||||||
Published: | 2011-12-01 | ||||||||||||||||||||||||
Updated: | 2019-10-09 | ||||||||||||||||||||||||
Summary: | A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases are SUSE open build service up to and including version 2.1.15 (for 2.1) and before version 2.3. | ||||||||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2011-4181 Source: CCN Type: Bugzilla Bug 734003 VUL-0: OBS information leak via unauthorized source access Source: CONFIRM Type: Issue Tracking https://bugzilla.suse.com/show_bug.cgi?id=734003 Source: CCN Type: openSUSE Web site openSUSE:Novell involvement - openSUSE Source: XF Type: UNKNOWN obs-cve20114181-info-disc(148087) Source: CONFIRM Type: Patch, Third Party Advisory https://github.com/openSUSE/open-build-service/commit/5281e4bff9df31f1f91e22a0d1e9086b93b23d7e | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |