CVE-2015-1613
EPSS 0.18%
Description
RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API method.
How to fix CVE-2015-1613
To remediate CVE-2015-1613, upgrade the affected package to a fixed version below.
- PyPI/rhodecode—upgrade to 2.2.7 or later
Is CVE-2015-1613 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.2.7