cbcvebase.
CVE-2012-4430
published 2012-10-10

CVE-2012-4430: The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain…

PriorityP418medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.68%
84.4th percentile
The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.

Affected

8 ranges
VendorProductVersion rangeFixed in
baculabacula< 5.2.115.2.11
baculabacula>= 0 < 5.2.6+dfsg-45.2.6+dfsg-4
baculabacula>= 0 < 5.2.6+dfsg-45.2.6+dfsg-4
baculabacula>= 0 < 5.2.6+dfsg-45.2.6+dfsg-4
baculabacula>= 0 < 5.2.6+dfsg-45.2.6+dfsg-4
debianbacula< bacula 5.2.6+dfsg-4 (bookworm)bacula 5.2.6+dfsg-4 (bookworm)
debiandebian_linux
debiandebian_linux

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.