schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.
References
Configurations
History
21 Nov 2024, 02:14
Type | Values Removed | Values Added |
---|---|---|
References | () http://hg.code.sf.net/p/roundup/code/rev/a403c29ffaf9 - | |
References | () http://www.debian.org/security/2016/dsa-3502 - | |
References | () https://sourceforge.net/p/roundup/code/ci/tip/tree/CHANGES.txt - Patch |
Information
Published : 2016-04-13 14:59
Updated : 2024-11-21 02:14
NVD link : CVE-2014-6276
Mitre link : CVE-2014-6276
CVE.ORG link : CVE-2014-6276
JSON object : View
Products Affected
roundup-tracker
- roundup
debian
- debian_linux
CWE
CWE-264
Permissions, Privileges, and Access Controls