CVE-2017-15210

In Kanboard before 1.0.47, by altering form data, an authenticated user can see thumbnails of pictures from a private project of another user.
References
Link Resource
http://openwall.com/lists/oss-security/2017/10/04/9 Mailing List Third Party Advisory VDB Entry
https://github.com/kanboard/kanboard/commit/7100f6de8a1f566e260b3e65312767e4cde112b1 Patch Third Party Advisory
https://kanboard.net/news/version-1.0.47 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kanboard:kanboard:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.9:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.10:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.11:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.12:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.13:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.14:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.15:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.16:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.17:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.18:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.19:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.20:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.21:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.22:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.23:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.24:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.25:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.26:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.27:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.28:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.29:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.30:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.31:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.31:beta0:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.31:beta1:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.32:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.32:beta0:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.32:beta1:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.33:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.34:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.35:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.36:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.38:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.39:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.40:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.41:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.42:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.43:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.44:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.45:*:*:*:*:*:*:*
cpe:2.3:a:kanboard:kanboard:1.0.46:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-10-11 01:32

Updated : 2024-02-04 19:29


NVD link : CVE-2017-15210

Mitre link : CVE-2017-15210

CVE.ORG link : CVE-2017-15210


JSON object : View

Products Affected

kanboard

  • kanboard
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor