Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j59j-h3g7-cpmf

Опубликовано: 01 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.1

Описание

Roundup xml-rpc server improper check of property permissions

The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.

Пакеты

Наименование

roundup

pip
Затронутые версииВерсия исправления

< 1.4.5

1.4.5

EPSS

Процентиль: 64%
0.0047
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-284

Связанные уязвимости

ubuntu
больше 17 лет назад

The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.

nvd
больше 17 лет назад

The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.

debian
больше 17 лет назад

The xml-rpc server in Roundup 1.4.4 does not check property permission ...

EPSS

Процентиль: 64%
0.0047
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-284