Zenoss CVE-2014-6260 Security Bypass Vulnerability
BID:71539
Info
Zenoss CVE-2014-6260 Security Bypass Vulnerability
| Bugtraq ID: | 71539 |
| Class: | Design Error |
| CVE: |
CVE-2014-6260 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2014 12:00AM |
| Updated: | Dec 08 2014 12:00AM |
| Credit: | Ryan Koppenhaver and Andy Schmitz of Matasano Security. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Zenoss CVE-2014-6260 Security Bypass Vulnerability
Zenoss is prone to a security-bypass vulnerability.
An attacker can leverage this issue to bypass security restrictions and gain access to potentially sensitive information. This may aid in further attacks.
Zenoss 4.2.4 is vulnerable.
Zenoss is prone to a security-bypass vulnerability.
An attacker can leverage this issue to bypass security restrictions and gain access to potentially sensitive information. This may aid in further attacks.
Zenoss 4.2.4 is vulnerable.
Exploit / POC
Zenoss CVE-2014-6260 Security Bypass Vulnerability
Attackers can exploit this issue using browser or readily available tools.
Attackers can exploit this issue using browser or readily available tools.
Solution / Fix
Zenoss CVE-2014-6260 Security Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Zenoss CVE-2014-6260 Security Bypass Vulnerability
References:
References: