VulnerabilityModified
CVE-2014-6275
If project webpages are hosted on the same server than FusionForge, it can allow users to incorrectly access on-disk private data in FusionForge.
MEDIUM 5.9EPSS 0.94%
Does this matter?
Lower severity and a low EPSS score (0.94%). Track it; it rarely justifies an emergency change on its own.
Description
FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages are hosted on the same server than FusionForge, it can allow users to incorrectly access on-disk private data in FusionForge.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.94% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- fusionforge/fusionforge · debian/debian linux
- Source
- security@debian.org
References
- http://lists.fusionforge.org/pipermail/fusionforge-general/2014-September/002824.htmlMailing List, Tool Signature
- https://security-tracker.debian.org/tracker/CVE-2014-6275Third Party Advisory
- http://lists.fusionforge.org/pipermail/fusionforge-general/2014-September/002824.htmlMailing List, Tool Signature
- https://security-tracker.debian.org/tracker/CVE-2014-6275Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.