Bugzilla – Bug 870606
VUL-0: CVE-2014-0594: obs-server: CSRF protection incorrectly disabled
Last modified: 2014-03-28 05:56:40 UTC
found by Curesec CSRF protection was incorrectly disabled in the open buildservice webui. fix: https://github.com/openSUSE/open-build-service/commit/2188c059b67b82171d0e28ef59f77e62d22a09d8
bugbot adjusting priority
Fixed in OBS 2.4.6 release and for upcoming 2.5.0.