CVE-2014-0594 Vulnerability Details

  /     /     /  

CVE-2014-0594 Metadata Quick Info

CVE Published: 08/06/2018 | CVE Updated: 16/09/2024 | CVE Year: 2014
Source: microfocus | Vendor: openSUSE | Product: Open Build Service
Status : PUBLISHED

CVE-2014-0594 Description

In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user\'s consent.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-352
CWE Name: CWE-352
Source: openSUSE

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).