CVE-2017-5188: Opensuse Open Build Service
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source directory during build, allowing leakage of private information.
Affected products
- Opensuse Open Build Service: up to and including 2.7.3
Published 2018-03-01. Last modified 2026-06-17.