CVE Vulnerabilities

CVE-2009-5015

Published: Nov 06, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The URL dispatch mechanism in TurboGears2 (aka tg2) before 2.0.2 exposes controller methods even when an @expose decoration is not used, which has unspecified impact and attack vectors.

Affected Software

NameVendorStart VersionEnd Version
Turbogears2Turbogears*2.1b2 (including)
Turbogears2Turbogears1.9.7a2 (including)1.9.7a2 (including)
Turbogears2Turbogears1.9.7a3 (including)1.9.7a3 (including)
Turbogears2Turbogears1.9.7a4 (including)1.9.7a4 (including)
Turbogears2Turbogears1.9.7b1 (including)1.9.7b1 (including)
Turbogears2Turbogears1.9.7b2 (including)1.9.7b2 (including)
Turbogears2Turbogears2.0-rc1 (including)2.0-rc1 (including)
Turbogears2Turbogears2.0.1 (including)2.0.1 (including)
Turbogears2Turbogears2.0b1 (including)2.0b1 (including)
Turbogears2Turbogears2.0b2 (including)2.0b2 (including)
Turbogears2Turbogears2.0b3 (including)2.0b3 (including)
Turbogears2Turbogears2.0b4 (including)2.0b4 (including)
Turbogears2Turbogears2.0b5 (including)2.0b5 (including)
Turbogears2Turbogears2.0b6 (including)2.0b6 (including)
Turbogears2Turbogears2.0b7 (including)2.0b7 (including)
Turbogears2Turbogears2.1a1 (including)2.1a1 (including)
Turbogears2Turbogears2.1a2 (including)2.1a2 (including)
Turbogears2Turbogears2.1a3 (including)2.1a3 (including)
Turbogears2Turbogears2.1b1 (including)2.1b1 (including)
Turbogears2Ubuntuupstream*

References