A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.