CVE Vulnerabilities

CVE-2005-4851

Improper Authentication

Published: Dec 31, 2005 | Modified: Jul 31, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

eZ publish 3.4.4 through 3.7 before 20050722 applies certain permissions on the node level, which allows remote authenticated users to bypass the original permissions on embedded objects in XML fields and read these objects.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Ez_publish Ez 3.4.4 (including) 3.7 (including)
Ezpublish Ubuntu dapper *
Ezpublish Ubuntu edgy *
Ezpublish Ubuntu feisty *
Ezpublish Ubuntu gutsy *

Potential Mitigations

References