The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-03-29T18:00:00

Updated: 2018-03-29T17:57:01

Reserved: 2014-07-22T00:00:00


Link: CVE-2014-5028

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-03-29T18:29:00.277

Modified: 2018-04-24T12:58:15.873


Link: CVE-2014-5028

JSON object: View

cve-icon Redhat Information

No data.

CWE