CVE-2015-2298: Infoleak
Published Jan 12, 2018
·Updated
node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper substring check when exporting a padID.
Affected Software
3 affected components
Etherpad Etherpad=1.5.0
Etherpad Etherpad=1.5.0-d
Etherpad Etherpad=1.5.1
Remediation
Patch Available
Event History
Jan 12, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2298?
CVE-2015-2298 is categorized as a medium severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2015-2298?
To fix CVE-2015-2298, upgrade Etherpad to version 1.5.2 or later.
3
What versions of Etherpad are affected by CVE-2015-2298?
CVE-2015-2298 affects Etherpad versions 1.5.0 and 1.5.1.
4
What kind of attack is possible with CVE-2015-2298?
CVE-2015-2298 allows remote attackers to potentially obtain sensitive information by exploiting an improper check during the export of a padID.
5
Is CVE-2015-2298 a critical vulnerability?
No, CVE-2015-2298 is not classified as critical, but it still poses a risk to sensitive information.