Field Assessment
AI analysis pending.
Exhibit — Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
GitHub PoC Links
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2013-3703
Severity
HIGH
CVSS
8.8
EPSS
0.93%
Original Filing — NVD Description
The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or remove user roles from packages and/or project meta data.