PT-2014-8901 · Zenoss · Zenoss Core
Published
2014-12-15
·
Updated
2016-03-21
·
CVE-2014-9247
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zenoss Core versions through 5 Beta 3
Description
The issue allows remote authenticated users to obtain sensitive information, including user account, e-mail address, and role information, by visiting the ZenUsers (also known as User Manager) page.
Recommendations
For versions through 5 Beta 3, consider restricting access to the ZenUsers page until a fix is available. As a temporary workaround, limit the privileges of authenticated users to minimize the risk of sensitive information exposure.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zenoss Core