CVE-2015-2204
Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 3.11% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- evergreen-ils/evergreen
- Source
- cve@mitre.org
References
- http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9Issue Tracking, Release Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7Issue Tracking, Release Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4Issue Tracking, Release Notes
- http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/Issue Tracking, Patch, Release Notes
- http://git.evergreen-ils.org/?p=Evergreen.git%3Ba=commit%3Bh=3a0f1cc7b2efa517ee4cd4c6a682237554fed307
- http://www.openwall.com/lists/oss-security/2015/03/04/3Issue Tracking, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/72889Third Party Advisory, VDB Entry
- https://bugs.launchpad.net/evergreen/+bug/1424755Issue Tracking, Patch, Vendor Advisory
- http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9Issue Tracking, Release Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7Issue Tracking, Release Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4Issue Tracking, Release Notes
- http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/Issue Tracking, Patch, Release Notes
- http://git.evergreen-ils.org/?p=Evergreen.git%3Ba=commit%3Bh=3a0f1cc7b2efa517ee4cd4c6a682237554fed307
- http://www.openwall.com/lists/oss-security/2015/03/04/3Issue Tracking, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/72889Third Party Advisory, VDB Entry
- https://bugs.launchpad.net/evergreen/+bug/1424755Issue Tracking, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.