Open Build Service
25 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Open Build Service, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
Open Build Service CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 25 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High10
- Medium13
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Open Build Service.
- CVE-2022-21949Multiple XXE vulnerabilities in OBS8.8
- CVE-2021-36777login-proxy sends password to attacker-provided domain8.1
- CVE-2020-8031obs: Stored XSS6.3
- CVE-2018-12475obs-service-download_files allows downloading from localhost or intranet hosts6.5
- CVE-2020-8021unauthorized read access to files where sourceaccess is disabled via a crafted _service file in Open Build Service5.3
- CVE-2020-8020Persistent XSS in markdown parser used by obs-server6.5
- CVE-2019-3685Missing TLS certificate validation for HTTPS connections in osc7.4
- CVE-2018-12479Request controller allows to create requests with arbitrary request IDs6.5
- CVE-2018-12474Crafted service parameters allows to induce unexpected behaviour in obs-service-tar_scm5.4
- CVE-2018-12477obs-service-refresh_patches can be tricked into deleting '..' or other unrelated directories3.5
- CVE-2018-12478obs-service-replace_using_package_version allows to specify arbitrary input files4.8
- CVE-2018-12473path traversal in obs-service-tar_scm3.1
- CVE-2018-12467delete package via link exploit in open buildservice6.0
- CVE-2018-12466openbuildservice allowed deleting packages via project links4.4
- CVE-2011-4183open build service allows anyone to upload rpms6.5
Product grouping is registry-driven, with AI assist and human review. How it works