Seafile Server before 3.1.2 and Server Professional Edition before 3.1.0 allow local users to gain privileges via vectors related to ccnet handling user accounts.
References
Link | Resource |
---|---|
https://manual.seafile.com/changelog/server-changelog.html | Release Notes |
https://manual.seafile.com/changelog/changelog-for-seafile-professional-server.html | Release Notes |
https://exchange.xforce.ibmcloud.com/vulnerabilities/95458 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/69360 | Third Party Advisory VDB Entry |
http://www.openwall.com/lists/oss-security/2014/08/24/3 | Mailing List |
Information
Published : 2018-03-19 14:29
Updated : 2018-04-20 07:55
NVD link : CVE-2014-5443
Mitre link : CVE-2014-5443
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
seafile
- seafile_server