Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T05:10:15.332Z

Reserved: 2015-03-03T00:00:00

Link: CVE-2015-2204

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-02-01T17:29:01.167

Modified: 2024-11-21T02:26:59.840

Link: CVE-2015-2204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.