CVE-2015-2204
Last modified
CVE-2015-2204 is a vulnerability of currently unknown severity. Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.. EPSS estimates a 3.17% chance of exploitation in the next 30 days.
Description
Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Evergreen-Ils | Evergreen | < 2.5.9 |
| Evergreen-Ils | Evergreen | >= 2.6.0, < 2.6.7 |
| Evergreen-Ils | Evergreen | >= 2.7.0, < 2.7.4 |
References
- http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9Issue Tracking, Release Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7Issue Tracking, Release Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4Issue Tracking, Release Notes
- http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/Issue Tracking, Patch, Release Notes
- http://www.openwall.com/lists/oss-security/2015/03/04/3Issue Tracking, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/72889Third Party Advisory, VDB Entry
- https://bugs.launchpad.net/evergreen/+bug/1424755Issue Tracking, Patch, Vendor Advisory
- http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9Issue Tracking, Release Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7Issue Tracking, Release Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4Issue Tracking, Release Notes
- http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/Issue Tracking, Patch, Release Notes
- http://www.openwall.com/lists/oss-security/2015/03/04/3Issue Tracking, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/72889Third Party Advisory, VDB Entry
- https://bugs.launchpad.net/evergreen/+bug/1424755Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-2204?
How severe is CVE-2015-2204?
How do I fix CVE-2015-2204?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-2197Cross-site scripting (XSS) vulnerability in the Entity API m…
- CVE-2015-2198Multiple cross-site scripting (XSS) vulnerabilities in edit_…
- CVE-2015-2199Multiple SQL injection vulnerabilities in the WonderPlugin A…
- CVE-2015-2201Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows Vi…7.2
- CVE-2015-2202Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows ad…7.2
- CVE-2015-2203Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticate…
- CVE-2015-2206libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0…
- CVE-2015-2207Multiple cross-site scripting (XSS) vulnerabilities in NetCr…5.4
- CVE-2015-2208The saveObject function in moadmin.php in phpMoAdmin 1.1.2 a…
- CVE-2015-2209DLGuard 4.5 allows remote attackers to obtain the installati…
- CVE-2015-2210The help window in Epicor CRS Retail Store before 3.2.03.01.…
- CVE-2015-2212Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
Are you affected by CVE-2015-2204?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
