a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled This issue affects: Open Build Service versions prior to 2.10.5.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Open_build_service | Opensuse | * | 2.10.5 (excluding) |
| Obs-build | Ubuntu | bionic | * |
| Obs-build | Ubuntu | eoan | * |
| Obs-build | Ubuntu | focal | * |
| Obs-build | Ubuntu | groovy | * |
| Obs-build | Ubuntu | hirsute | * |
| Obs-build | Ubuntu | impish | * |
| Obs-build | Ubuntu | kinetic | * |
| Obs-build | Ubuntu | lunar | * |
| Obs-build | Ubuntu | mantic | * |
| Obs-build | Ubuntu | oracular | * |
| Obs-build | Ubuntu | trusty | * |
| Obs-build | Ubuntu | xenial | * |