A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows authenticated users to generate HTTP request against internal networks and potentially downloading data that is exposed there. This issue affects: openSUSE Open Build Service .
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Open_build_service | Opensuse | - (including) | - (including) |
Open-build-service | Ubuntu | bionic | * |
Open-build-service | Ubuntu | kinetic | * |
Open-build-service | Ubuntu | lunar | * |
Open-build-service | Ubuntu | mantic | * |
Open-build-service | Ubuntu | trusty | * |