Vulnerabilities > Opensuse > Open Build Service > 0.5.12

DATE CVE VULNERABILITY TITLE RISK
2018-06-08 CVE-2014-0593 Improper Input Validation vulnerability in Opensuse Open Build Service
The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS).
network
low complexity
opensuse CWE-20
critical
9.8
2018-03-20 CVE-2011-3178 Code Injection vulnerability in Opensuse Open Build Service
In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to execute shellcode.
network
low complexity
opensuse CWE-94
8.8