The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.reviewboard.org/docs/releasenotes/reviewboard/2.0.4 | vendor advisory |
http://www.openwall.com/lists/oss-security/2014/07/22/12 | third party advisory mailing list |
https://bugzilla.redhat.com/show_bug.cgi?id=1123692 | issue tracking third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/94813 | vdb entry third party advisory |
https://www.reviewboard.org/news/2014/07/22/review-board-1-7-27-and-2-0-3-security-releases | vendor advisory |
https://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.27 | vendor advisory |