schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published: 2016-04-13T14:00:00

Updated: 2024-08-06T12:10:13.271Z

Reserved: 2014-09-09T00:00:00

Link: CVE-2014-6276

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2016-04-13T14:59:00.140

Modified: 2024-11-21T02:14:04.753

Link: CVE-2014-6276

cve-icon Redhat

No data.