Open build service
This hub aggregates every CVE we track for Open build service, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
25
CVEs tracked
0
Critical
10
High
0
In CISA KEV
Severity distribution
MEDIUM13HIGH10LOW2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Open build service.
- CVE-2022-21949Multiple XXE vulnerabilities in OBS8.8
- CVE-2021-36777login-proxy sends password to attacker-provided domain8.1
- CVE-2020-8031obs: Stored XSS6.3
- CVE-2018-12475obs-service-download_files allows downloading from localhost or intranet hosts6.5
- CVE-2020-8021unauthorized read access to files where sourceaccess is disabled via a crafted _service file in Open Build Service5.3
- CVE-2020-8020Persistent XSS in markdown parser used by obs-server6.5
- CVE-2019-3685Missing TLS certificate validation for HTTPS connections in osc7.4
- CVE-2018-12479Request controller allows to create requests with arbitrary request IDs6.5
- CVE-2018-12474Crafted service parameters allows to induce unexpected behaviour in obs-service-tar_scm5.4
- CVE-2018-12477obs-service-refresh_patches can be tricked into deleting '..' or other unrelated directories3.5
- CVE-2018-12478obs-service-replace_using_package_version allows to specify arbitrary input files4.8
- CVE-2018-12473path traversal in obs-service-tar_scm3.1
- CVE-2018-12467delete package via link exploit in open buildservice6.0
- CVE-2018-12466openbuildservice allowed deleting packages via project links4.4
- CVE-2011-4183open build service allows anyone to upload rpms6.5
Product normalization is registry-driven with AI assist and human review. How it works