Bugzilla – Bug 1143652
AUDIT-FIND: obs-service-set_version: path traversal
Last modified: 2024-05-17 11:53:11 UTC
> takes an potentially absolute path to what files should be modified. Only files in the build root should be allowed.
That's true, but the attack primitive is very limited. Opened https://github.com/openSUSE/obs-service-set_version/issues/66 to increase visibility.