VulnerabilityModified
CVE-2014-5028
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging…
MEDIUM 6.5EPSS 1.64%
Does this matter?
Lower severity and a low EPSS score (1.64%). Track it; it rarely justifies an emergency change on its own.
Description
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- reviewboard/review board
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2014/07/22/12Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1123692Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94813Third Party Advisory, VDB Entry
- https://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.27Vendor Advisory
- https://www.reviewboard.org/docs/releasenotes/reviewboard/2.0.4Vendor Advisory
- https://www.reviewboard.org/news/2014/07/22/review-board-1-7-27-and-2-0-3-security-releasesVendor Advisory
- http://www.openwall.com/lists/oss-security/2014/07/22/12Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1123692Issue Tracking, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94813Third Party Advisory, VDB Entry
- https://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.27Vendor Advisory
- https://www.reviewboard.org/docs/releasenotes/reviewboard/2.0.4Vendor Advisory
- https://www.reviewboard.org/news/2014/07/22/review-board-1-7-27-and-2-0-3-security-releasesVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.