{"id":"CVE-2015-0260","aliases":["PYSEC-2015-29","PYSEC-2015-32"],"url":"https://o3.security/vulnerability/CVE-2015-0260","summary":"RhodeCode and Kallithea are vulnerable to sensitive information disclosure","details":"RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method.","published":"2022-05-13T01:26:14Z","modified":"2024-09-24T21:02:04.220827Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"PyPI","name":"rhodecode","fixedVersion":"2.2.7"},{"ecosystem":"PyPI","name":"kallithea","fixedVersion":"0.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-0260"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/100888"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/kallithea/PYSEC-2015-29.yaml"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/rhodecode/PYSEC-2015-32.yaml"},{"type":"WEB","url":"https://kallithea-scm.org/repos/kallithea/changeset/5923d74742879b812965568475e21c3496d722a9"},{"type":"WEB","url":"https://kallithea-scm.org/security/cve-2015-0260.html"},{"type":"WEB","url":"https://rhodecode.com/blog/rhodecode-enterprise-security-release"},{"type":"WEB","url":"https://web.archive.org/web/20150321135511/http://www.securityfocus.com/bid/72573"},{"type":"WEB","url":"http://seclists.org/oss-sec/2015/q1/505"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-09-24T21:02:04.220827Z"}}