First published: Fri Sep 18 2015(Updated: )
IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunistic circumstances by leveraging incorrect notification delivery.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Xcode | <=6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5909 is considered a medium severity vulnerability due to the potential exposure of sensitive build information.
To fix CVE-2015-5909, update to Apple Xcode version 7.0 or later where the vulnerability has been addressed.
CVE-2015-5909 may allow remote attackers to gain access to potentially sensitive build information via improperly restricted repository email lists.
CVE-2015-5909 affects Apple Xcode versions prior to 7.0, specifically up to and including version 6.4.
CVE-2015-5909 involves the IDE Xcode Server component, which manages project repositories and notifications.