CVE-2014-5028
Summary
| CVE | CVE-2014-5028 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-29 18:29:00 UTC |
| Updated | 2018-04-24 12:58:00 UTC |
| Description | The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Reviewboard | Review Board | All | All | All | All |
| Application | Reviewboard | Review Board | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Review Board 1.7.27 Release Notes | Documentation | Review Board | CONFIRM | www.reviewboard.org | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| 1123692 – (CVE-2014-5027, CVE-2014-5028) CVE-2014-5027 CVE-2014-5028 ReviewBoard: two flaws fixed in the 1.7.27 release | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| Review Board 1.7.27 and 2.0.4 security releases | News | Review Board | CONFIRM | www.reviewboard.org | Vendor Advisory |
| oss-security - Re: CVE requests for Review Board | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| Review Board 2.0.4 Release Notes | Documentation | Review Board | CONFIRM | www.reviewboard.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.