CVE Vulnerabilities

CVE-2018-1000875

Published: Dec 20, 2018 | Modified: Jul 08, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Berkeley Open Infrastructure for Network Computing BOINC Server and Website Code version 0.9-1.0.2 contains a CWE-302: Authentication Bypass by Assumed-Immutable Data vulnerability in Website Terms of Service Acceptance Page that can result in Access to any user account. This attack appear to be exploitable via Specially crafted URL. This vulnerability appears to have been fixed in 1.0.3.

Affected Software

NameVendorStart VersionEnd Version
Boinc_serverUniversityofcalifornia1.0.0 (including)1.0.3 (excluding)
BoincUbuntubionic*
BoincUbuntucosmic*
BoincUbuntudisco*
BoincUbuntueoan*
BoincUbuntufocal*
BoincUbuntugroovy*
BoincUbuntuhirsute*
BoincUbuntuimpish*
BoincUbuntutrusty*
BoincUbuntuxenial*

References