CVE-2015-2203: Infoleak
Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFFLOGIN permission to obtain sensitive settings history information by leveraging listing of open-ils.pcrud as a controller in the IDL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2203?
CVE-2015-2203 has been assigned a medium severity rating due to its potential to expose sensitive settings history to unauthorized users.
How do I fix CVE-2015-2203?
To fix CVE-2015-2203, update Evergreen to a version that is not vulnerable, such as any version beyond 2.7.4.
Who is affected by CVE-2015-2203?
CVE-2015-2203 affects remote authenticated users with STAFF_LOGIN permission in Evergreen versions 2.5.9, 2.6.7, and 2.7.4.
What specific information can be accessed due to CVE-2015-2203?
CVE-2015-2203 allows access to sensitive settings history information through the identification of open-ils.pcrud as a controller in the IDL.
What versions of Evergreen are vulnerable to CVE-2015-2203?
Evergreen versions 2.5.9, 2.6.7, and 2.7.4 are vulnerable to CVE-2015-2203.