CVE-2014-6275
Summary
| CVE | CVE-2014-6275 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-02 22:15:00 UTC |
| Updated | 2020-01-14 17:38:00 UTC |
| Description | FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages are hosted on the same server than FusionForge, it can allow users to incorrectly access on-disk private data in FusionForge. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Fusionforge | Fusionforge | All | All | All | All |
| Application | Fusionforge | Fusionforge | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2014-6275 | MISC | security-tracker.debian.org | Third Party Advisory |
| [Fusionforge-general] FusionForge 5.3.2 + CVE-2014-6275 | MISC | lists.fusionforge.org | Mailing List, Tool Signature |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.