CVE-2009-2171

Publication date 23 June 2009

Last updated 24 July 2024


Ubuntu priority

Description

Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts, which allows remote authenticated users to read another user's artefact.

Read the notes from the security team

Status

Package Ubuntu Release Status
mahara 9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release

Notes


jdstrand

per fmarier, 8.10 and 9.04 are not affected