CVE-2013-4411
published 2019-12-03CVE-2013-4411: Review Board: URL processing gives unauthorized users access to review lists
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
1.35%
68.8th percentile
Review Board: URL processing gives unauthorized users access to review lists
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| review_board | review_board | — | — |
| reviewboard | reviewboard | >= 1.6 < 1.6.19 | 1.6.19 |
| reviewboard | reviewboard | >= 1.7 < 1.7.15 | 1.7.15 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4410 CVE-2013-4411 ReviewBoard: various flaws [epel-6]
bugzilla·2013-10-10·CVSS 7.5
CVE-2013-4410 [HIGH] CVE-2013-4410 CVE-2013-4411 ReviewBoard: various flaws [epel-6]
CVE-2013-4410 CVE-2013-4411 ReviewBoard: various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for ReviewBoard:
Bugzilla
CVE-2013-4410 CVE-2013-4411 ReviewBoard: various flaws [fedora-all]
bugzilla·2013-10-10·CVSS 7.5
CVE-2013-4410 [HIGH] CVE-2013-4410 CVE-2013-4411 ReviewBoard: various flaws [fedora-all]
CVE-2013-4410 CVE-2013-4411 ReviewBoard: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multi
Bugzilla
CVE-2013-4411 ReviewBoard: URL processing allows unauthorized users to view review lists
bugzilla·2013-10-08·CVSS 4.3
CVE-2013-4411 [MEDIUM] CVE-2013-4411 ReviewBoard: URL processing allows unauthorized users to view review lists
CVE-2013-4411 ReviewBoard: URL processing allows unauthorized users to view review lists
=== Summary ===
A flaw in the Review Board dashboard URL-processing logic makes it
possible for a user to construct a URL that would reveal review
requests for review groups to which the user does not belong.
=== Affected Deployments ===
All Review Board deployments are vulnerable to this flaw.
=== Scope ===
This flaw is only of particular risk to those deployments relying on
review groups to restrict access to private reviews, such as those
that may contain confidential intellectual property or provide
information about embargoed security issues.
This attack is possible to execute remotely through the Review Board
dashboard.
=== Resolution ===
Code was added to the URL handling to return a 404 (n
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/120619.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-October/119819.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-October/119820.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-October/119830.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-October/119831.htmlhttp://www.securityfocus.com/bid/63023https://access.redhat.com/security/cve/cve-2013-4411https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4411https://exchange.xforce.ibmcloud.com/vulnerabilities/88061https://security-tracker.debian.org/tracker/CVE-2013-4411http://lists.fedoraproject.org/pipermail/package-announce/2013-November/120619.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-October/119819.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-October/119820.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-October/119830.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-October/119831.htmlhttp://www.securityfocus.com/bid/63023https://access.redhat.com/security/cve/cve-2013-4411https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4411https://exchange.xforce.ibmcloud.com/vulnerabilities/88061https://security-tracker.debian.org/tracker/CVE-2013-4411
2019-12-03
Published