A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows authenticated users to generate HTTP request against internal networks and potentially downloading data that is exposed there. This issue affects: openSUSE Open Build Service .
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Open_build_service | Opensuse | - (including) | - (including) |
| Open-build-service | Ubuntu | bionic | * |
| Open-build-service | Ubuntu | kinetic | * |
| Open-build-service | Ubuntu | lunar | * |
| Open-build-service | Ubuntu | mantic | * |
| Open-build-service | Ubuntu | oracular | * |
| Open-build-service | Ubuntu | trusty | * |