CVE-2015-0260
medium
CVSS v3
—
CVSS v2
4.0
VIR risk
4.0
Description
RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://rhodecode.com/blog/rhodecode-enterprise-security-release/
Vendor advisory: secalert@redhat.com — https://kallithea-scm.org/security/cve-2015-0260.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| kallithea-scm | kallithea | 0.1 | |
| rhodecode | rhodecode_enterprise | {"endIncluding":"2.2.6"} | |
References
- http://seclists.org/oss-sec/2015/q1/505
- http://www.securityfocus.com/bid/72573
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100888
- https://kallithea-scm.org/security/cve-2015-0260.html
- https://rhodecode.com/blog/rhodecode-enterprise-security-release/
- https://nvd.nist.gov/vuln/detail/CVE-2015-0260
- https://github.com/pypa/advisory-database/tree/main/vulns/kallithea/PYSEC-2015-29.yaml
- https://github.com/pypa/advisory-database/tree/main/vulns/rhodecode/PYSEC-2015-32.yaml
- https://kallithea-scm.org/repos/kallithea/changeset/5923d74742879b812965568475e21c3496d722a9
- https://rhodecode.com/blog/rhodecode-enterprise-security-release
- https://web.archive.org/web/20150321135511/http://www.securityfocus.com/bid/72573
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.