VYPR
Unrated severityNVD Advisory· Published Oct 9, 2018· Updated Sep 16, 2024

Request controller allows to create requests with arbitrary request IDs

CVE-2018-12479

Description

A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS by specifying crafted request IDs. Affected releases are openSUSE Open Build Service: versions prior to 01b015ca2a320afc4fae823465d1e72da8bd60df.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Open Build Service remote DoS via crafted request IDs due to improper input validation.

Vulnerability

The request controller in openSUSE Open Build Service versions prior to commit 01b015ca2a320afc4fae823465d1e72da8bd60df contains an improper input validation vulnerability [1]. This allows remote attackers to cause a denial of service by specifying crafted request IDs that the controller does not properly validate.

Exploitation

An attacker can send a crafted request to the Open Build Service with an arbitrary request ID. No authentication is required, and the attack can be performed remotely over HTTP. The request ID is used in a way that leads to resource exhaustion or crash, resulting in denial of service.

Impact

Successful exploitation results in a denial of service, making the Open Build Service unavailable to legitimate users. The attack affects the availability of the service without requiring any special privileges.

Mitigation

The vulnerability is fixed in commit 01b015ca2a320afc4fae823465d1e72da8bd60df [1]. Users should update their Open Build Service installations to include this commit or a later version. No workarounds are documented.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Range: < 01b015ca2a320afc4fae823465d1e72da8bd60df
  • openSUSE/Open Build Servicev5
    Range: unspecified

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.