VulnerabilityModified
CVE-2015-3163
The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote authenticated users to modify power types and key types via navigating to $BEAKER/powertypes and $BEAKER/keytypes respectively.
MEDIUM 4.3EPSS 1.09%
Does this matter?
Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.
Description
The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote authenticated users to modify power types and key types via navigating to $BEAKER/powertypes and $BEAKER/keytypes respectively.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.09% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- redhat/beaker
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2015/05/08/1Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/74567Third Party Advisory, VDB Entry
- https://beaker-project.org/jenkins-results/beaker-review-checks-docs/995/documentation/_build/html/whats-new/release-20.htmlRelease Notes, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1215034Exploit, Issue Tracking, Patch, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2015/05/08/1Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/74567Third Party Advisory, VDB Entry
- https://beaker-project.org/jenkins-results/beaker-review-checks-docs/995/documentation/_build/html/whats-new/release-20.htmlRelease Notes, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1215034Exploit, Issue Tracking, Patch, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.