Описание
The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml.
Ссылки
- Issue TrackingRelease Notes
- Issue TrackingRelease Notes
- Issue TrackingRelease Notes
- Issue TrackingRelease Notes
- Issue TrackingMailing ListThird Party Advisory
- Issue TrackingPatch
- Issue TrackingRelease Notes
- Issue TrackingRelease Notes
- Issue TrackingRelease Notes
- Issue TrackingRelease Notes
- Issue TrackingMailing ListThird Party Advisory
- Issue TrackingPatch
Уязвимые конфигурации
Конфигурация 1Версия до 2.5.9 (исключая)Версия от 2.6.0 (включая) до 2.6.7 (исключая)Версия от 2.7.0 (включая) до 2.7.4 (исключая)
Одно из
cpe:2.3:a:evergreen-ils:evergreen:*:*:*:*:*:*:*:*
cpe:2.3:a:evergreen-ils:evergreen:*:*:*:*:*:*:*:*
cpe:2.3:a:evergreen-ils:evergreen:*:*:*:*:*:*:*:*
EPSS
Процентиль: 41%
0.00192
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 6.5
github
больше 3 лет назад
The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml.
EPSS
Процентиль: 41%
0.00192
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-200