CVE-2015-2204
Last modified
CVE-2015-2204 is a vulnerability of currently unknown severity. Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.. EPSS estimates a 3.17% chance of exploitation in the next 30 days.
Description
Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Evergreen-Ils | Evergreen | < 2.5.9 |
| Evergreen-Ils | Evergreen | >= 2.6.0, < 2.6.7 |
| Evergreen-Ils | Evergreen | >= 2.7.0, < 2.7.4 |
References
- http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9Issue Tracking, Release Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7Issue Tracking, Release Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4Issue Tracking, Release Notes
- http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/Issue Tracking, Patch, Release Notes
- http://www.openwall.com/lists/oss-security/2015/03/04/3Issue Tracking, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/72889Third Party Advisory, VDB Entry
- https://bugs.launchpad.net/evergreen/+bug/1424755Issue Tracking, Patch, Vendor Advisory
- http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9Issue Tracking, Release Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7Issue Tracking, Release Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4Issue Tracking, Release Notes
- http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/Issue Tracking, Patch, Release Notes
- http://www.openwall.com/lists/oss-security/2015/03/04/3Issue Tracking, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/72889Third Party Advisory, VDB Entry
- https://bugs.launchpad.net/evergreen/+bug/1424755Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-2204?
How severe is CVE-2015-2204?
How do I fix CVE-2015-2204?
Are you affected by CVE-2015-2204?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
