Bugzilla – Bug 723788
VUL-0: CVE-2011-3178: obs webui code injection
Last modified: 2017-03-10 17:33:32 UTC
the obs server webui did not sanitize the 'scheduler' parameter when calling the mkdiststats script. Remote attackers could exploit that to inject code. https://github.com/openSUSE/open-build-service/commit/cbfe2ed36dd77c0843702935dea7f914bb599201
CVE-2011-3178
fix is in 2.1.13