Vulnerability Description
Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Evergreen-Ils | Evergreen | < 2.5.9 |
Related Weaknesses (CWE)
References
- http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9Issue TrackingRelease Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7Issue TrackingRelease Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4Issue TrackingRelease Notes
- http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/Issue TrackingPatchRelease Notes
- http://git.evergreen-ils.org/?p=Evergreen.git%3Ba=commit%3Bh=3a0f1cc7b2efa517ee4
- http://www.openwall.com/lists/oss-security/2015/03/04/3Issue TrackingMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/72889Third Party AdvisoryVDB Entry
- https://bugs.launchpad.net/evergreen/+bug/1424755Issue TrackingPatchVendor Advisory
- http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9Issue TrackingRelease Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7Issue TrackingRelease Notes
- http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4Issue TrackingRelease Notes
- http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/Issue TrackingPatchRelease Notes
- http://git.evergreen-ils.org/?p=Evergreen.git%3Ba=commit%3Bh=3a0f1cc7b2efa517ee4
- http://www.openwall.com/lists/oss-security/2015/03/04/3Issue TrackingMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/72889Third Party AdvisoryVDB Entry
FAQ
What is CVE-2015-2204?
CVE-2015-2204 is a vulnerability with a CVSS score of 7.5 (HIGH). Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveragi...
How severe is CVE-2015-2204?
CVE-2015-2204 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-2204?
Check the references section above for vendor advisories and patch information. Affected products include: Evergreen-Ils Evergreen.