CVE-2005-4854
Publication date 31 December 2005
Last updated 17 July 2025
Ubuntu priority
Description
eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authenticated users to obtain sensitive information about changes to content in arbitrary folders.