CVE-2015-8748

Loading...

General

Score:5.0/10.0
Severity:Medium
Category:Access Control Error

Impact Metrics

Confidentiality:None
Integrity:Partial
Availability:None

Exploitability Metrics

Access Vector:Network
Access Complexity:Low
Authentication:None

Relative vulnerabilities

CVE-2015-8747

Published on 03/02/16 - Updated on 06/12/16

Description

Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacharacters in the user name, as demonstrated by ".*".

Category: Access Control Error

CWE-264 (Permissions, Privileges, and Access Control)
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Security Notices

US National Vulnerability DatabaseCVE-2015-8748
Debian DSA-3462-1
Debian LTSDLA-403-1

Exploits

No exploits available for this CVE in our database.

Relative technologies

VendorProduct
radicaleradicale

Share this vulnerability with:

Twitter Facebook LinkedIn Mail