RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API method.
References
Link | Resource |
---|---|
https://rhodecode.com/blog/rhodecode-enterprise-security-release/ | Vendor Advisory |
https://rhodecode.com/blog/rhodecode-enterprise-security-release/ | Vendor Advisory |
Configurations
History
21 Nov 2024, 02:25
Type | Values Removed | Values Added |
---|---|---|
References | () https://rhodecode.com/blog/rhodecode-enterprise-security-release/ - Vendor Advisory |
Information
Published : 2015-02-16 15:59
Updated : 2024-11-21 02:25
NVD link : CVE-2015-1613
Mitre link : CVE-2015-1613
CVE.ORG link : CVE-2015-1613
JSON object : View
Products Affected
rhodecode
- rhodecode_enterprise
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor