IgnitionServer Entry Deletion Access Validation Checking Vulnerability
BID:13654
Info
IgnitionServer Entry Deletion Access Validation Checking Vulnerability
| Bugtraq ID: | 13654 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2005 12:00AM |
| Updated: | May 17 2005 12:00AM |
| Credit: | Discovered by Keith Gable <[email protected]>. |
| Vulnerable: |
The Ignition Project ignitionServer 0.3.6 The Ignition Project ignitionServer 0.3.4 a beta4 The Ignition Project ignitionServer 0.3.3 beta3 The Ignition Project ignitionServer 0.3.2 beta2 The Ignition Project ignitionServer 0.3.1 -P1 The Ignition Project ignitionServer 0.3.1 beta1 The Ignition Project ignitionServer 0.3.1 The Ignition Project ignitionServer 0.3 .0 |
| Not Vulnerable: |
The Ignition Project ignitionServer 0.3.6 -P1 |
Discussion
IgnitionServer Entry Deletion Access Validation Checking Vulnerability
ignitionServer is prone to an issue that allows hosts to delete access entries created by owners. This occurs because access validation is never performed when the host deletes the entry.
This issue was addressed in ignitionServer 0.3.6-P1.
ignitionServer is prone to an issue that allows hosts to delete access entries created by owners. This occurs because access validation is never performed when the host deletes the entry.
This issue was addressed in ignitionServer 0.3.6-P1.
Exploit / POC
IgnitionServer Entry Deletion Access Validation Checking Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
IgnitionServer Entry Deletion Access Validation Checking Vulnerability
Solution:
A fix is available.
The Ignition Project ignitionServer 0.3 .0
The Ignition Project ignitionServer 0.3.1
The Ignition Project ignitionServer 0.3.1 beta1
The Ignition Project ignitionServer 0.3.1 -P1
The Ignition Project ignitionServer 0.3.2 beta2
The Ignition Project ignitionServer 0.3.3 beta3
The Ignition Project ignitionServer 0.3.4 a beta4
The Ignition Project ignitionServer 0.3.6
Solution:
A fix is available.
The Ignition Project ignitionServer 0.3 .0
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
The Ignition Project ignitionServer 0.3.1
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
The Ignition Project ignitionServer 0.3.1 beta1
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
The Ignition Project ignitionServer 0.3.1 -P1
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
The Ignition Project ignitionServer 0.3.2 beta2
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
The Ignition Project ignitionServer 0.3.3 beta3
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
The Ignition Project ignitionServer 0.3.4 a beta4
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
The Ignition Project ignitionServer 0.3.6
-
The Ignition Project ignitionServer 0.3.6-P1
http://www.ignition-project.com/download/
References
IgnitionServer Entry Deletion Access Validation Checking Vulnerability
References:
References:
- Security Bulletin: Hosts can delete access entries added by owners (The Ignition Project)
- The Ignition Project Homepage (The Ignition Project)