{"api_version":"1","generated_at":"2026-07-23T10:06:29+00:00","cve":"CVE-2015-3400","urls":{"html":"https://cve.report/CVE-2015-3400","api":"https://cve.report/api/cve/CVE-2015-3400.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-3400","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-3400"},"summary":{"title":"CVE-2015-3400","description":"sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to the shared zfs file system, which might allow remote authenticated users to obtain sensitive information by reading shared files.","state":"PUBLISHED","assigner":"mitre","published_at":"2017-10-18 15:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/74272","name":"http://www.securityfocus.com/bid/74272","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Debian zfsonlinux 'nfs.c' Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/zfsonlinux/zfs/pull/2790/commits","name":"https://github.com/zfsonlinux/zfs/pull/2790/commits","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"Rewrite of nfs.c to keep options per host separated. by FransUrbo · Pull Request #2790 · openzfs/zfs · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/zfsonlinux/zfs/issues/3319","name":"https://github.com/zfsonlinux/zfs/issues/3319","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"security issue: sharenfs always gives read access for world · Issue #3319 · openzfs/zfs · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/FransUrbo/zfs/commit/99aa4d2b4fd12c6bef62d02ffd1b375ddd42fcf4","name":"https://github.com/FransUrbo/zfs/commit/99aa4d2b4fd12c6bef62d02ffd1b375ddd42fcf4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"Move nfs.c:foreach_nfs_shareopt() to libshare.c:foreach_shareopt() · FransUrbo/zfs@99aa4d2 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2015/04/22/4","name":"http://www.openwall.com/lists/oss-security/2015/04/22/4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","VDB Entry"],"title":"oss-security - Re: CVE Request for ZFS on Linux","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-3400","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3400","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"3400","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zfsonlinux","cpe5":"zfs","cpe6":"0.6.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T05:47:57.467Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"74272","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/74272"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/FransUrbo/zfs/commit/99aa4d2b4fd12c6bef62d02ffd1b375ddd42fcf4"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/zfsonlinux/zfs/issues/3319"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/zfsonlinux/zfs/pull/2790/commits"},{"name":"[oss-security] 20150422 Re: CVE Request for ZFS on Linux","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2015/04/22/4"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-04-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to the shared zfs file system, which might allow remote authenticated users to obtain sensitive information by reading shared files."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"74272","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/74272"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/FransUrbo/zfs/commit/99aa4d2b4fd12c6bef62d02ffd1b375ddd42fcf4"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/zfsonlinux/zfs/issues/3319"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/zfsonlinux/zfs/pull/2790/commits"},{"name":"[oss-security] 20150422 Re: CVE Request for ZFS on Linux","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2015/04/22/4"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-3400","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to the shared zfs file system, which might allow remote authenticated users to obtain sensitive information by reading shared files."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"74272","refsource":"BID","url":"http://www.securityfocus.com/bid/74272"},{"name":"https://github.com/FransUrbo/zfs/commit/99aa4d2b4fd12c6bef62d02ffd1b375ddd42fcf4","refsource":"CONFIRM","url":"https://github.com/FransUrbo/zfs/commit/99aa4d2b4fd12c6bef62d02ffd1b375ddd42fcf4"},{"name":"https://github.com/zfsonlinux/zfs/issues/3319","refsource":"CONFIRM","url":"https://github.com/zfsonlinux/zfs/issues/3319"},{"name":"https://github.com/zfsonlinux/zfs/pull/2790/commits","refsource":"CONFIRM","url":"https://github.com/zfsonlinux/zfs/pull/2790/commits"},{"name":"[oss-security] 20150422 Re: CVE Request for ZFS on Linux","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2015/04/22/4"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2015-3400","datePublished":"2017-10-18T15:00:00.000Z","dateReserved":"2015-04-22T00:00:00.000Z","dateUpdated":"2024-08-06T05:47:57.467Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-10-18 15:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:zfsonlinux:zfs:0.6.4:*:*:*:*:*:*:*","matchCriteriaId":"DB2FE587-3D13-40F6-938D-715B75D13906"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"3400","Ordinal":"1","Title":"CVE-2015-3400","CVE":"CVE-2015-3400","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"3400","Ordinal":"1","NoteData":"sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to the shared zfs file system, which might allow remote authenticated users to obtain sensitive information by reading shared files.","Type":"Description","Title":"CVE-2015-3400"},{"CveYear":"2015","CveId":"3400","Ordinal":"2","NoteData":"2017-10-18","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"3400","Ordinal":"3","NoteData":"2017-10-18","Type":"Other","Title":"Modified"}]}}}