Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j556-q367-2gw6

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

Roundup sensitive data disclosure vulnerability

schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.

Пакеты

Наименование

roundup

pip
Затронутые версииВерсия исправления

< 1.5.1

1.5.1

EPSS

Процентиль: 33%
0.0013
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 10 лет назад

schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.

CVSS3: 4.3
nvd
почти 10 лет назад

schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.

CVSS3: 4.3
debian
почти 10 лет назад

schema.py in Roundup before 1.5.1 does not properly limit attributes i ...

EPSS

Процентиль: 33%
0.0013
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-200