Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.
History

Mon, 24 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Feb 2025 19:45:00 +0000

Type Values Removed Values Added
Description Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.
Title Feedback response viewing and deletions did not respect Separate Groups mode
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published: 2025-02-24T19:39:23.646Z

Updated: 2025-02-24T20:11:24.973Z

Reserved: 2025-02-12T13:29:39.335Z

Link: CVE-2025-26526

cve-icon Vulnrichment

Updated: 2025-02-24T19:58:49.230Z

cve-icon NVD

Status : Received

Published: 2025-02-24T20:15:33.263

Modified: 2025-02-24T20:15:33.263

Link: CVE-2025-26526

cve-icon Redhat

No data.