Total vulnerabilities in the database
Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by leveraging listing of open-ils.pcrud as a controller in the IDL.
Software | From | Fixed in |
---|---|---|
evergreen-ils / evergreen | 2.7.4 | 2.7.4.x |
evergreen-ils / evergreen | 2.6.7 | 2.6.7.x |
evergreen-ils / evergreen | 2.5.9 | 2.5.9.x |