CVE-2014-6276

medium

Description

schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.

References

https://sourceforge.net/p/roundup/code/ci/tip/tree/CHANGES.txt

http://www.debian.org/security/2016/dsa-3502

http://hg.code.sf.net/p/roundup/code/rev/a403c29ffaf9

Details

Source: Mitre, NVD

Published: 2016-04-13

Updated: 2016-04-20

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Severity: Medium