Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4...
Vulnerability Description
Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-2204
Credits & Attribution
No credits recorded in the NVD database.
References
- http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4
- http://www.openwall.com/lists/oss-security/2015/03/04/3
- http://www.securityfocus.com/bid/72889
- http://git.evergreen-ils.org/?p=Evergreen.git%3Ba=commit%3Bh=3a0f1cc7b2efa517ee4cd4c6a682237554fed307
- http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7
- http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9
- http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9/
- https://bugs.launchpad.net/evergreen/+bug/1424755
Affected Vendor
evergreen-ils
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.