CVE-2014-6276
MEDIUMRoundup < 1.5.1 - Authenticated Sensitive Information Exposure via Default User Permissions
Title source: llmDescription
schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.
References (3)
Core 3
Core References
Various Sources x_refsource_confirm
http://hg.code.sf.net/p/roundup/code/rev/a403c29ffaf9
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2016/dsa-3502
Patch x_refsource_confirm
https://sourceforge.net/p/roundup/code/ci/tip/tree/CHANGES.txt
Scores
CVSS v3
4.3
EPSS
0.0154
EPSS Percentile
72.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-264
Status
published
Products (4)
debian/debian_linux
7.0
debian/debian_linux
8.0
pypi/roundup
0 - 1.5.1PyPI
roundup-tracker/roundup
< 1.5.0
Published
Apr 13, 2016
Tracked Since
Feb 18, 2026