CVE-2015-2172
published 2015-03-30CVE-2015-2172: DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain…
PriorityP434medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.86%
85.2th percentile
DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dokuwiki | < dokuwiki 0.0.20140929.d-1 (bookworm) | dokuwiki 0.0.20140929.d-1 (bookworm) |
| dokuwiki | dokuwiki | >= 0 < 0.0.20140929.d-1 | 0.0.20140929.d-1 |
| dokuwiki | dokuwiki | >= 0 < 0.0.20140929.d-1 | 0.0.20140929.d-1 |
| dokuwiki | dokuwiki | >= 0 < 0.0.20140929.d-1 | 0.0.20140929.d-1 |
| dokuwiki | dokuwiki | >= 0 < 0.0.20140929.d-1 | 0.0.20140929.d-1 |
| dokuwiki | dokuwiki | >= 2014-05-05 < 2014-05-05d | 2014-05-05d |
| dokuwiki | dokuwiki | >= 2014-09-29 < 2014-09-29c | 2014-09-29c |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8xqm-cgj8-jqmr: DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to
ghsa_unreviewed·2022-05-14
CVE-2015-2172 [MEDIUM] CWE-284 GHSA-8xqm-cgj8-jqmr: DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to
DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.
OSV
CVE-2015-2172: DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to
osv·2015-03-30·CVSS 6.5
CVE-2015-2172 [MEDIUM] CVE-2015-2172: DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to
DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.
Debian
CVE-2015-2172: dokuwiki - DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permi...
vendor_debian·2015·CVSS 6.5
CVE-2015-2172 [MEDIUM] CVE-2015-2172: dokuwiki - DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permi...
DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.
Scope: local
bookworm: resolved (fixed in 0.0.20140929.d-1)
bullseye: resolved (fixed in 0.0.20140929.d-1)
forky: resolved (fixed in 0.0.20140929.d-1)
sid: resolved (fixed in 0.0.20140929.d-1)
trixie: resolved (fixed in 0.0.20140929.d-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5277 glibc: data corruption while reading the NSS files database
bugzilla·2015-09-14·CVSS 7.2
CVE-2015-5277 [HIGH] CVE-2015-5277 glibc: data corruption while reading the NSS files database
CVE-2015-5277 glibc: data corruption while reading the NSS files database
It was discovered that the nss_files backend for the Name Service Switch in glibc would return incorrect data to applications or corrupt the heap (depending on adjacent heap contents), potentially resulting in arbitrary code execution.
Discussion:
External references:
https://sourceware.org/bugzilla/show_bug.cgi?id=17079
---
Upstream commit:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commitdiff;h=ac60763eac3d43b7234dd21286ad3ec3f17957fc
---
Acknowledgements:
This issue was discovered by Sumit Bose and Lukáš Slebodník of Red Hat.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2015:2172 https://rhn.redhat.com/errata/RHSA-2015-2172.html
---
This
Bugzilla
CVE-2015-2172 dokuwiki: privilege escalation in RPC API [fedora-all]
bugzilla·2015-03-02·CVSS 6.5
CVE-2015-2172 [MEDIUM] CVE-2015-2172 dokuwiki: privilege escalation in RPC API [fedora-all]
CVE-2015-2172 dokuwiki: privilege escalation in RPC API [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
Bugzilla
CVE-2015-2172 dokuwiki: privilege escalation in RPC API
bugzilla·2015-03-02·CVSS 6.5
CVE-2015-2172 [MEDIUM] CVE-2015-2172 dokuwiki: privilege escalation in RPC API
CVE-2015-2172 dokuwiki: privilege escalation in RPC API
The following security-related flaw has been fixed in the 2014-09-29c release (of 2015-02-25) of dokuwiki:
"Security Hotfix 2014-09-29c: fixes privilege escalation in RPC API"
Details per upstream issue:
There's a security hole in the ACL plugins remote API component. The plugin failes to check for superuser permissions before executing ACL addition or deletion. This means everybody with permissions to call the XMLRPC API also has permissions to set up their own ACL rules and thus circumventing any existing rules.
Upstream issue:
https://github.com/splitbrain/dokuwiki/issues/1056
Upstream patch:
https://github.com/splitbrain/dokuwiki/commit/4970ad24ce49ec76a0ee67bca7594f918ced2f5f
Discussion:
Created dokuwiki tracking bugs f
Bugzilla
CVE-2015-2172 dokuwiki: privilege escalation in RPC API [epel-all]
bugzilla·2015-03-02·CVSS 6.5
CVE-2015-2172 [MEDIUM] CVE-2015-2172 dokuwiki: privilege escalation in RPC API [epel-all]
CVE-2015-2172 dokuwiki: privilege escalation in RPC API [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
http://advisories.mageia.org/MGASA-2015-0093.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152994.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/153062.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/153266.htmlhttp://www.openwall.com/lists/oss-security/2015/03/02/2http://www.securityfocus.com/bid/72827https://github.com/splitbrain/dokuwiki/commit/4970ad24ce49ec76a0ee67bca7594f918ced2f5fhttps://github.com/splitbrain/dokuwiki/issues/1056https://www.dokuwiki.org/changeshttp://advisories.mageia.org/MGASA-2015-0093.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152994.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/153062.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/153266.htmlhttp://www.openwall.com/lists/oss-security/2015/03/02/2http://www.securityfocus.com/bid/72827https://github.com/splitbrain/dokuwiki/commit/4970ad24ce49ec76a0ee67bca7594f918ced2f5fhttps://github.com/splitbrain/dokuwiki/issues/1056https://www.dokuwiki.org/changes
2015-03-30
Published