2017-10-16 12:31:07 -04:00
{
2018-06-11 11:12:30 +02:00
"CVE_data_meta" : {
"ASSIGNER" : "security@suse.de" ,
2018-06-11 10:31:52 -04:00
"DATE_PUBLIC" : "2011-12-06" ,
2018-06-11 11:12:30 +02:00
"ID" : "CVE-2011-4181" ,
"STATE" : "PUBLIC" ,
"TITLE" : "open build service information leak via unauthorized source access"
2017-10-16 12:31:07 -04:00
} ,
2018-06-11 11:12:30 +02:00
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "open build service" ,
"version" : {
"version_data" : [
{
"affected" : "<=" ,
2018-06-11 11:28:15 +02:00
"version_value" : "2.1.15"
2018-06-11 11:12:30 +02:00
} ,
{
"affected" : "<" ,
2018-06-11 11:28:15 +02:00
"version_value" : "2.3"
2018-06-11 11:12:30 +02:00
}
]
}
}
]
} ,
"vendor_name" : "SUSE"
}
]
}
} ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2018-06-11 16:12:37 +02:00
"value" : "A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled\nAffected releases are SUSE open build service. Affected releases are up to and including version 2.1.15 (for 2.1) and before version 2.3."
2018-06-11 11:12:30 +02:00
}
]
} ,
"impact" : {
"cvss" : {
"attackComplexity" : "LOW" ,
"attackVector" : "NETWORK" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.3 ,
"baseSeverity" : "MEDIUM" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
"privilegesRequired" : "LOW" ,
"scope" : "UNCHANGED" ,
"userInteraction" : "NONE" ,
"vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" ,
"version" : "3.0"
}
} ,
"problemtype" : {
"problemtype_data" : [
2017-10-16 12:31:07 -04:00
{
2018-06-11 11:12:30 +02:00
"description" : [
{
"lang" : "eng" ,
"value" : "CWE-284"
}
]
2017-10-16 12:31:07 -04:00
}
]
2018-06-11 11:12:30 +02:00
} ,
"references" : {
"reference_data" : [
{
"name" : "https://github.com/openSUSE/open-build-service/commit/5281e4bff9df31f1f91e22a0d1e9086b93b23d7e" ,
"refsource" : "CONFIRM" ,
"url" : "https://github.com/openSUSE/open-build-service/commit/5281e4bff9df31f1f91e22a0d1e9086b93b23d7e"
} ,
{
"name" : "https://bugzilla.suse.com/show_bug.cgi?id=734003" ,
"refsource" : "CONFIRM" ,
"url" : "https://bugzilla.suse.com/show_bug.cgi?id=734003"
}
]
} ,
"source" : {
"defect" : [
"734003"
] ,
"discovery" : "INTERNAL"
2017-10-16 12:31:07 -04:00
}
2018-06-11 11:28:15 +02:00
}