CVE-2014-5028
Last modified
CVE-2014-5028 is a vulnerability of currently unknown severity. The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.. EPSS estimates a 1.73% chance of exploitation in the next 30 days.
Description
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Reviewboard | Review Board | > 1.7.0, < 1.7.27 |
| Reviewboard | Review Board | >= 2.0, < 2.0.4 |
References
- http://www.openwall.com/lists/oss-security/2014/07/22/12Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1123692Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94813Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2014/07/22/12Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1123692Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94813Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-5028?
How severe is CVE-2014-5028?
How do I fix CVE-2014-5028?
Are you affected by CVE-2014-5028?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
