Junglewise Threat Intelligence

CVE-2015-0260: PYSEC-2015-32 - RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_re

CVE-2015-0260 · Severity: low · CVSS 3.1 · Published 2015-02-16

Technologies: kallithea (PyPI). Vendors: PyPI.

Executive brief

RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method.

Affected products

  • PyPI rhodecode
  • PyPI kallithea

Related threats