OBS worker VM escape via relative symbolic links
CVE-2017-5188
5MEDIUM
What is CVE-2017-5188?
The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source directory during build, allowing leakage of private information.
Affected Version(s)
open build service < 20170320