Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3521

Опубликовано: 16 сент. 2014
Источник: redhat
CVSS2: 5.5

Описание

The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access restrictions via a crafted URL.

It was discovered that various components in the luci site extension-related URLs were not properly restricted to administrative users. A remote, authenticated attacker could escalate their privileges to perform certain actions that should be restricted to administrative users, such as adding users and systems, and viewing log data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5congaAffected
Red Hat Enterprise Linux 6luciNot affected
Red Hat Enterprise Linux 5congaFixedRHSA-2014:119416.09.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=1112813luci: unauthorized administrative access granted to non-administrative users

5.5 Medium

CVSS2

Связанные уязвимости

nvd
около 11 лет назад

The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access restrictions via a crafted URL.

github
больше 3 лет назад

The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access restrictions via a crafted URL.

oracle-oval
около 11 лет назад

ELSA-2014-1194: conga security and bug fix update (MODERATE)

5.5 Medium

CVSS2