CVE Vulnerabilities

CVE-2024-30187

Improper Preservation of Permissions

Published: Mar 25, 2024 | Modified: May 28, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Anope before 2.0.15 does not prevent resetting the password of a suspended account.

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

NameVendorStart VersionEnd Version
AnopeAnope*2.0.15 (excluding)
AnopeUbuntudevel*
AnopeUbuntuesm-apps/bionic*
AnopeUbuntuesm-apps/xenial*
AnopeUbuntuesm-infra/focal*
AnopeUbuntufocal*
AnopeUbuntujammy*
AnopeUbuntumantic*
AnopeUbuntunoble*
AnopeUbuntuupstream*

References