VulnerabilityModified
CVE-2008-1475
The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.
MEDIUM 6.4EPSS 1.76%
Does this matter?
Lower severity and a low EPSS score (1.76%). Track it; it rarely justifies an emergency change on its own.
Description
The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 1.76% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- roundup-tracker/roundup
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29336Vendor Advisory
- http://secunia.com/advisories/29375Vendor Advisory
- http://secunia.com/advisories/30274
- http://secunia.com/advisories/32805
- http://security.gentoo.org/glsa/glsa-200805-21.xml
- http://sourceforge.net/tracker/index.php?func=detail&aid=1907211&group_id=31577&atid=402788
- http://www.securityfocus.com/bid/28238
- http://www.vupen.com/english/advisories/2008/0891
- https://bugzilla.redhat.com/show_bug.cgi?id=436546
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41240
- https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00264.html
- https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00375.html
- https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00452.html
- https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00478.html
- http://secunia.com/advisories/29336Vendor Advisory
- http://secunia.com/advisories/29375Vendor Advisory
- http://secunia.com/advisories/30274
- http://secunia.com/advisories/32805
- http://security.gentoo.org/glsa/glsa-200805-21.xml
- http://sourceforge.net/tracker/index.php?func=detail&aid=1907211&group_id=31577&atid=402788
- http://www.securityfocus.com/bid/28238
- http://www.vupen.com/english/advisories/2008/0891
- https://bugzilla.redhat.com/show_bug.cgi?id=436546
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41240
- https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00264.html
- https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00375.html
- https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00452.html
- https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00478.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.