FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages are hosted on the same server than FusionForge, it can allow users to incorrectly access on-disk private data in FusionForge.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-6161 | FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages are hosted on the same server than FusionForge, it can allow users to incorrectly access on-disk private data in FusionForge. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: debian
Published:
Updated: 2024-08-06T12:10:13.234Z
Reserved: 2014-09-09T00:00:00
Link: CVE-2014-6275
No data.
Status : Modified
Published: 2020-01-02T22:15:11.317
Modified: 2024-11-21T02:14:04.637
Link: CVE-2014-6275
No data.
OpenCVE Enrichment
No data.
EUVD