RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API method.
References
Link | Resource |
---|---|
https://rhodecode.com/blog/rhodecode-enterprise-security-release/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2015-02-16 15:59
Updated : 2024-02-04 18:35
NVD link : CVE-2015-1613
Mitre link : CVE-2015-1613
CVE.ORG link : CVE-2015-1613
JSON object : View
Products Affected
rhodecode
- rhodecode_enterprise
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor