CVE-2015-0260

medium
Published 2015-02-16 · Modified 2024-04-29
CVSS v3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v2
4.0
VIR risk
4.0

Description

RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://rhodecode.com/blog/rhodecode-enterprise-security-release/

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://kallithea-scm.org/security/cve-2015-0260.html

Package impact

EcosystemPackageVulnerableFixed
python PyPIrhodecode<2.2.72.2.7
python PyPIkallithea<0.20.2

Application impact

VendorProductVersionsFixed
kallithea-scmkallithea0.1
rhodecoderhodecode_enterprise{"endIncluding":"2.2.6"}

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.