Back

MEDIUM

RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API method

Published Feb 16, 2015

Description

RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API method.

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 16, 2015
Updated Sep 16, 2024
Reserved Feb 16, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a