RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API method.
References
Link | Resource |
---|---|
https://rhodecode.com/blog/rhodecode-enterprise-security-release/ | Vendor Advisory |
Configurations
Information
Published : 2015-02-16 07:59
Updated : 2015-02-17 09:13
NVD link : CVE-2015-1613
Mitre link : CVE-2015-1613
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
rhodecode
- rhodecode_enterprise