CVE Published: 01/09/2020 |
CVE Updated: 17/09/2024 |
CVE Year: 2018 Source: microfocus |
Vendor: openSUSE |
Product: Open Build Service Status : PUBLISHED
CVE-2018-12475 Description
A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows authenticated users to generate HTTP request against internal networks and potentially downloading data that is exposed there. This issue affects: openSUSE Open Build Service .
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N