CVE-2015-3163
Summary
| CVE | CVE-2015-3163 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-06 21:29:00 UTC |
| Updated | 2020-03-09 18:39:00 UTC |
| Description | The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote authenticated users to modify power types and key types via navigating to $BEAKER/powertypes and $BEAKER/keytypes respectively. |
Risk And Classification
Problem Types: CWE-284
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Beaker CVE-2015-3163 Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| 1215034 – (CVE-2015-3163) anonymous users can modify key types and power types | CONFIRM | bugzilla.redhat.com | Exploit, Issue Tracking, Patch, Third Party Advisory, VDB Entry |
| 404 Not Found | CONFIRM | beaker-project.org | Release Notes, Vendor Advisory |
| oss-security - beaker vulns fixed in version 20.1 | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.