CVE-2014-6276
13.04.2016, 14:59
schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.Enginsight
| Vendor | Product | Version |
|---|---|---|
| roundup-tracker | roundup | 𝑥 ≤ 1.5.0 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References