Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3521

Опубликовано: 16 сент. 2014
Источник: redhat
CVSS2: 5.5
EPSS Низкий

Описание

The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access restrictions via a crafted URL.

It was discovered that various components in the luci site extension-related URLs were not properly restricted to administrative users. A remote, authenticated attacker could escalate their privileges to perform certain actions that should be restricted to administrative users, such as adding users and systems, and viewing log data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5congaAffected
Red Hat Enterprise Linux 6luciNot affected
Red Hat Enterprise Linux 5congaFixedRHSA-2014:119416.09.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=1112813luci: unauthorized administrative access granted to non-administrative users

EPSS

Процентиль: 36%
0.00152
Низкий

5.5 Medium

CVSS2

Связанные уязвимости

nvd
почти 11 лет назад

The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access restrictions via a crafted URL.

github
больше 3 лет назад

The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access restrictions via a crafted URL.

oracle-oval
почти 11 лет назад

ELSA-2014-1194: conga security and bug fix update (MODERATE)

EPSS

Процентиль: 36%
0.00152
Низкий

5.5 Medium

CVSS2