SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-6276

schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.

MEDIUM 4.3EPSS 1.55%

Does this matter?

Lower severity and a low EPSS score (1.55%). Track it; it rarely justifies an emergency change on its own.

Description

schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.

CVSS 3.0
4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
1.55% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
roundup-tracker/roundup · debian/debian linux
Source
security@debian.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.