CVE-2015-1613

medium
Published 2015-02-16 · Modified 2023-11-08
CVSS v3
CVSS v2
4.0
VIR risk
4.0

Description

RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API method.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://rhodecode.com/blog/rhodecode-enterprise-security-release/

Package impact

EcosystemPackageVulnerableFixed
python PyPIrhodecode<2.2.72.2.7

Application impact

VendorProductVersionsFixed
rhodecoderhodecode_enterprise{"endIncluding":"2.2.6"}

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.