CVE-2014-0594: Opensuse Open Build Service

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.

Affected products

  • Opensuse Open Build Service: before 2.4.6 (fixed in 2.4.6)

Published 2018-06-08. Last modified 2026-06-17.