CVE-2014-5028: Infoleak
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5028?
CVE-2014-5028 has been assigned a moderate severity level due to its potential to expose sensitive information.
How do I fix CVE-2014-5028?
To fix CVE-2014-5028, upgrade Review Board to version 1.7.27 or later, or to version 2.0.4 or later.
What are the affected versions of Review Board for CVE-2014-5028?
The affected versions for CVE-2014-5028 are Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4.
Who is impacted by CVE-2014-5028?
Remote authenticated users can be impacted by CVE-2014-5028 as it allows them to bypass access restrictions.
What type of vulnerability is CVE-2014-5028?
CVE-2014-5028 is a type of access control vulnerability that enables unauthorized information disclosure from repository files.