CVE-2015-2204
Summary
| CVE | CVE-2015-2204 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-01 17:29:00 UTC |
| Updated | 2023-11-07 02:25:00 UTC |
| Description | Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Evergreen-ils | Evergreen | All | All | All | All |
| Application | Evergreen-ils | Evergreen | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug #1424755 “Org Unit Setting View Permissions Can Be Bypassed” : Bugs : Evergreen | CONFIRM | bugs.launchpad.net | Issue Tracking, Patch, Vendor Advisory |
| evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7 | CONFIRM | evergreen-ils.org | Issue Tracking, Release Notes |
| git.evergreen-ils.org Git | git.evergreen-ils.org | ||
| SECURITY RELEASES: Evergreen 2.7.4, 2.6.7, and 2.5.9 – Evergreen ILS | CONFIRM | evergreen-ils.org | Issue Tracking, Patch, Release Notes |
| evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4 | CONFIRM | evergreen-ils.org | Issue Tracking, Release Notes |
| evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9 | CONFIRM | evergreen-ils.org | Issue Tracking, Release Notes |
| git.evergreen-ils.org Git - Evergreen.git/commit | CONFIRM | git.evergreen-ils.org | Issue Tracking, Patch |
| Evergreen CVE-2015-2204 Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| oss-security - Re: CVE request - Evergreen | MLIST | www.openwall.com | Issue Tracking, Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.