CVE-2015-7317
medium
CVSS v3
6.8
CVSS v2
4.9
VIR risk
6.8
Description
Kupu 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, and 4.2.0 through 4.2.7 allows remote authenticated users to edit Kupu settings.
Predictions
Exploit likelihood
77%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://plone.org/security/hotfix/20150910/privilege-escalation-in-kupu
Vendor advisory: cve@mitre.org — https://plone.org/security/hotfix/20150910
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| kupu_project | kupu | {"endIncluding":"1.4.16"} | |
| plone | plone | 3.3 | |
| plone | plone | 3.3.1 | |
| plone | plone | 3.3.2 | |
| plone | plone | 3.3.3 | |
| plone | plone | 3.3.4 | |
| plone | plone | 3.3.5 | |
| plone | plone | 3.3.6 | |
| plone | plone | 4.0 | |
| plone | plone | 4.0.1 | |
| plone | plone | 4.0.2 | |
| plone | plone | 4.0.3 | |
| plone | plone | 4.0.4 | |
| plone | plone | 4.0.5 | |
| plone | plone | 4.0.6.1 | |
| plone | plone | 4.0.7 | |
| plone | plone | 4.0.8 | |
| plone | plone | 4.0.9 | |
| plone | plone | 4.0.10 | |
| plone | plone | 4.1 | |
| plone | plone | 4.1.1 | |
| plone | plone | 4.1.2 | |
| plone | plone | 4.1.3 | |
| plone | plone | 4.1.4 | |
| plone | plone | 4.1.5 | |
| plone | plone | 4.1.6 | |
| plone | plone | 4.2 | |
| plone | plone | 4.2.1 | |
| plone | plone | 4.2.2 | |
| plone | plone | 4.2.3 | |
| plone | plone | 4.2.4 | |
| plone | plone | 4.2.5 | |
| plone | plone | 4.2.6 | |
| plone | plone | 4.2.7 | |
References
- http://www.openwall.com/lists/oss-security/2015/09/22/15
- https://bugzilla.redhat.com/show_bug.cgi?id=1264799
- https://plone.org/security/hotfix/20150910
- https://plone.org/security/hotfix/20150910/privilege-escalation-in-kupu
- http://www.openwall.com/lists/oss-security/2015/09/22/15
- https://bugzilla.redhat.com/show_bug.cgi?id=1264799
- https://plone.org/security/hotfix/20150910
- https://plone.org/security/hotfix/20150910/privilege-escalation-in-kupu
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.