CVE-2018-12474
Estado: ModificadaCrítica (9.8)—
Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: versions prior to 51a17c553b6ae2598820b7a90fd0c11502a49106.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.36%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-12474",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "security@opentext.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@opentext.com",
"affectedData": [
{
"vendor": "openSUSE",
"product": "Open Build Service",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "51a17c553b6ae2598820b7a90fd0c11502a49106",
"versionType": "custom"
}
]
}
]
}
],
"published": "2018-10-09T13:29:00.400",
"references": [
{
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1107507",
"source": "security@opentext.com"
},
{
"url": "https://github.com/openSUSE/obs-service-tar_scm/pull/254",
"source": "security@opentext.com"
},
{
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1107507",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/openSUSE/obs-service-tar_scm/pull/254",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@opentext.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: versions prior to 51a17c553b6ae2598820b7a90fd0c11502a49106."
},
{
"lang": "es",
"value": "Validación de entradas incorrecta en obs-service-tar_scm en Open Build Service permite que los atacantes remotos puedaqn acceder y extraer información fuera de la build actual o crear archivos en ubicaciones controladas por el atacante. Las versiones afectadas son openSUSE Open Build Service en versiones anteriores a la 51a17c553b6ae2598820b7a90fd0c11502a49106."
}
],
"lastModified": "2026-06-17T01:37:51.117",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:opensuse:tar_scm:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0076F11D-90A0-41F2-836B-B5A08EF34927",
"versionEndExcluding": "0.9.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@opentext.com"
}