{ "schema_version": "1.4.0", "id": "GHSA-c97p-7qc3-rpcv", "modified": "2022-05-14T03:44:32Z", "published": "2022-05-14T03:44:32Z", "aliases": [ "CVE-2015-2203" ], "details": "Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by leveraging listing of open-ils.pcrud as a controller in the IDL.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-2203" }, { "type": "WEB", "url": "https://bugs.launchpad.net/evergreen/+bug/1206589" }, { "type": "WEB", "url": "http://evergreen-ils.org/downloads/ChangeLog-2.5.8-2.5.9" }, { "type": "WEB", "url": "http://evergreen-ils.org/downloads/ChangeLog-2.6.6-2.6.7" }, { "type": "WEB", "url": "http://evergreen-ils.org/downloads/ChangeLog-2.7.3-2.7.4" }, { "type": "WEB", "url": "http://evergreen-ils.org/security-releases-evergreen-2-7-4-2-6-7-and-2-5-9" }, { "type": "WEB", "url": "http://git.evergreen-ils.org/?p=Evergreen.git;a=commit;h=ac588e879cf73ff1b65617e0bd273361d3529063" }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2015/03/04/3" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/72885" } ], "database_specific": { "cwe_ids": [ "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2018-02-01T17:29:00Z" } }