CVE-2015-2204: Infoleak
Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ousetting.ancestordefault to enforce viewperm when no auth token is provided.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2204?
CVE-2015-2204 has a medium severity rating due to its potential for unauthorized information disclosure.
How do I fix CVE-2015-2204?
To fix CVE-2015-2204, upgrade Evergreen to versions 2.5.9, 2.6.7, or 2.7.4 or later.
What systems are affected by CVE-2015-2204?
CVE-2015-2204 affects Evergreen versions prior to 2.5.9, 2.6.x versions before 2.6.7, and 2.7.x versions before 2.7.4.
What type of vulnerability is CVE-2015-2204?
CVE-2015-2204 is a remote access vulnerability that allows attackers to bypass access restrictions.
What can attackers access through CVE-2015-2204?
Attackers exploiting CVE-2015-2204 can obtain sensitive information about organizational unit settings.