{"id":"CVE-2014-6276","aliases":["PYSEC-2016-33"],"url":"https://o3.security/vulnerability/CVE-2014-6276","summary":"Roundup sensitive data disclosure vulnerability","details":"schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.","published":"2022-05-17T03:56:49Z","modified":"2024-10-26T22:49:52.038610Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":{"score":0.01548,"percentile":0.72885,"asOf":"2026-08-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"roundup","fixedVersion":"1.5.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-6276"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/roundup/PYSEC-2016-33.yaml"},{"type":"PACKAGE","url":"https://github.com/roundup-tracker/roundup"},{"type":"WEB","url":"https://sourceforge.net/p/roundup/code/ci/tip/tree/CHANGES.txt"},{"type":"WEB","url":"http://hg.code.sf.net/p/roundup/code/rev/a403c29ffaf9"},{"type":"WEB","url":"http://www.debian.org/security/2016/dsa-3502"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-10-26T22:49:52.038610Z"}}