{"api_version":"1","generated_at":"2026-07-23T08:05:11+00:00","cve":"CVE-2014-5028","urls":{"html":"https://cve.report/CVE-2014-5028","api":"https://cve.report/api/cve/CVE-2014-5028.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-5028","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-5028"},"summary":{"title":"CVE-2014-5028","description":"The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-03-29 18:29:00","updated_at":"2018-04-24 12:58:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.27","name":"https://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.27","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Review Board 1.7.27 Release Notes | Documentation | Review Board","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/94813","name":"reviewboard-cve20145028-sec-bypass(94813)","refsource":"XF","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1123692","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1123692","refsource":"CONFIRM","tags":["Issue Tracking","Third Party Advisory"],"title":"1123692 – (CVE-2014-5027, CVE-2014-5028) CVE-2014-5027 CVE-2014-5028 ReviewBoard: two flaws fixed in the 1.7.27 release","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.reviewboard.org/news/2014/07/22/review-board-1-7-27-and-2-0-3-security-releases","name":"https://www.reviewboard.org/news/2014/07/22/review-board-1-7-27-and-2-0-3-security-releases","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Review Board 1.7.27 and 2.0.4 security releases | News | Review Board","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2014/07/22/12","name":"[oss-security] 20140722 Re: CVE requests for Review Board","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE requests for Review Board","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.reviewboard.org/docs/releasenotes/reviewboard/2.0.4","name":"https://www.reviewboard.org/docs/releasenotes/reviewboard/2.0.4","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Review Board 2.0.4 Release Notes | Documentation | Review Board","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-5028","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-5028","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"5028","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"reviewboard","cpe5":"review_board","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"5028","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"reviewboard","cpe5":"review_board","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-5028","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://www.reviewboard.org/docs/releasenotes/reviewboard/2.0.4","refsource":"CONFIRM","url":"https://www.reviewboard.org/docs/releasenotes/reviewboard/2.0.4"},{"name":"[oss-security] 20140722 Re: CVE requests for Review Board","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2014/07/22/12"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=1123692","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1123692"},{"name":"reviewboard-cve20145028-sec-bypass(94813)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/94813"},{"name":"https://www.reviewboard.org/news/2014/07/22/review-board-1-7-27-and-2-0-3-security-releases","refsource":"CONFIRM","url":"https://www.reviewboard.org/news/2014/07/22/review-board-1-7-27-and-2-0-3-security-releases"},{"name":"https://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.27","refsource":"CONFIRM","url":"https://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.27"}]}},"nvd":{"publishedDate":"2018-03-29 18:29:00","lastModifiedDate":"2018-04-24 12:58:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:reviewboard:review_board:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0","versionEndExcluding":"2.0.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:reviewboard:review_board:*:*:*:*:*:*:*:*","versionStartExcluding":"1.7.0","versionEndExcluding":"1.7.27","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"5028","Ordinal":"72007","Title":"CVE-2014-5028","CVE":"CVE-2014-5028","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"5028","Ordinal":"1","NoteData":"The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.","Type":"Description","Title":null},{"CveYear":"2014","CveId":"5028","Ordinal":"2","NoteData":"2018-03-29","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"5028","Ordinal":"3","NoteData":"2018-03-29","Type":"Other","Title":"Modified"}]}}}