{ "id": "CVE-2011-0466", "sourceIdentifier": "cve@mitre.org", "published": "2011-04-10T02:51:19.383", "lastModified": "2024-11-21T01:24:03.157", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "The API in SUSE openSUSE Build Service (OBS) 2.0.x before 2.0.8 and 2.1.x before 2.1.6 allows attackers to bypass intended write-access restrictions and modify a (1) package or (2) project via unspecified vectors." }, { "lang": "es", "value": "La API en SUSE openSUSE Build Service (OBS) v2.0.x antes de v2.0.8 y v2.1.x antes de v2.1.6 permite a atacantes eludir restricciones intencionadas de acceso de escritura y modificar un (1) paquete o (2) proyecto, a trav\u00e9s de vectores no especificados." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P", "baseScore": 6.4, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 4.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-264" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.0:*:*:*:*:*:*:*", "matchCriteriaId": "B6A4DC80-D559-4516-B2B8-67A10FA5E672" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "030EA7EE-F788-4813-96E1-E6FC21F749B8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "5E1EED8C-ED06-40B1-8837-5319DB51009B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "16FBC9F4-BF69-4C8B-BC00-293BECF16624" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.0.3:*:*:*:*:*:*:*", "matchCriteriaId": "EA6C8261-DD6F-461A-9358-5BFFEF85AD62" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.0.4:*:*:*:*:*:*:*", "matchCriteriaId": "B9B75D0D-CC7A-4FE9-B71B-7A43D53DFAF3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.0.5:*:*:*:*:*:*:*", "matchCriteriaId": "9899C0E7-B19F-4266-A69A-E34EE09290A3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.0.6:*:*:*:*:*:*:*", "matchCriteriaId": "D85DAA0A-9A2E-4AEB-8C27-CB92A456CA39" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.0.7:*:*:*:*:*:*:*", "matchCriteriaId": "7B1B927A-15CE-433D-880F-4CECFB0FDC5D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.0.16:*:*:*:*:*:*:*", "matchCriteriaId": "5CF698A5-B2B7-4918-BC1E-7D807C4E18F7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.0.103:*:*:*:*:*:*:*", "matchCriteriaId": "2A82F5A8-8638-420C-9244-B9373EBF2B4F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.0.104:*:*:*:*:*:*:*", "matchCriteriaId": "6DEF91AA-F15A-4A79-AB09-AF4F5D76E582" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.0.106:*:*:*:*:*:*:*", "matchCriteriaId": "51F8840F-EBBE-4A27-A523-E1A94411FC12" } ] } ] }, { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.1:*:*:*:*:*:*:*", "matchCriteriaId": "45A10192-12C2-45D2-BA51-EBA142550EC5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.1.0:*:*:*:*:*:*:*", "matchCriteriaId": "E2B03379-450D-4598-8809-B5670A266020" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "289AEAF3-45E3-42F0-810D-8BC8B7F24717" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "85393DBB-CC63-4646-913D-922A6B437919" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.1.3:*:*:*:*:*:*:*", "matchCriteriaId": "D713D43B-919C-4648-A6C8-C3DCE787AA03" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.1.4:*:*:*:*:*:*:*", "matchCriteriaId": "0B352186-C486-4F15-B7F1-2061AC45EFB9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.1.5:*:*:*:*:*:*:*", "matchCriteriaId": "14605A5E-7381-4CF5-AC58-4C23B20636E9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:novell:opensuse_build_service:2.1.5.1:*:*:*:*:*:*:*", "matchCriteriaId": "F52F2BCB-1214-4581-9237-FD15C3CBDFA9" } ] } ] } ], "references": [ { "url": "http://news.opensuse.org/2011/03/02/build-service-team-releases-new-versions-fixing-security-problems/", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://news.opensuse.org/2011/03/02/build-service-team-releases-new-versions-fixing-security-problems/", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] } ] }