CVE-2014-0593

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
08/06/2018
Last modified:
07/11/2023

Description

The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). In versions prior to 0.5.3-1.1 this script did not properly sanitize the input provided by the user, allowing for code execution on the executing server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:opensuse:open_build_service:*:*:*:*:*:*:*:* 0.5.3 (including) 1.1 (excluding)