CVE-2012-3473
medium
CVSS v3
—
CVSS v2
6.4
VIR risk
6.4
Description
The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://github.com/ushahidi/Ushahidi_Web/commit/f67f4ad
Vendor advisory: secalert@redhat.com — https://github.com/ushahidi/Ushahidi_Web/commit/13ca6f4
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ushahidi | ushahidi_platform | {"endIncluding":"2.4.1"} | |
| ushahidi | ushahidi_platform | 1.0 | |
| ushahidi | ushahidi_platform | 1.2 | |
| ushahidi | ushahidi_platform | 2.0 | |
| ushahidi | ushahidi_platform | 2.1 | |
| ushahidi | ushahidi_platform | 2.2 | |
| ushahidi | ushahidi_platform | 2.2.1 | |
| ushahidi | ushahidi_platform | 2.3.1 | |
| ushahidi | ushahidi_platform | 2.3.2 | |
| ushahidi | ushahidi_platform | 2.4 | |
References
- http://openwall.com/lists/oss-security/2012/08/09/5
- https://github.com/ushahidi/Ushahidi_Web/commit/13ca6f4
- https://github.com/ushahidi/Ushahidi_Web/commit/f67f4ad
- http://openwall.com/lists/oss-security/2012/08/09/5
- https://github.com/ushahidi/Ushahidi_Web/commit/13ca6f4
- https://github.com/ushahidi/Ushahidi_Web/commit/f67f4ad
CWEs
CWE-287
Verify integrity in audit chain (admin only). AS-IS.