Moderate severityNVD Advisory· Published Aug 11, 2009· Updated Apr 23, 2026
CVE-2009-2737
CVE-2009-2737
Description
The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions does not properly check permissions, which allows remote authenticated users with edit or create privileges for a class to modify arbitrary items within that class, as demonstrated by editing all queries, modifying settings, and adding roles to users.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
RoundupPyPI | >= 1.2, < 1.2.1 | 1.2.1 |
RoundupPyPI | >= 1.4, < 1.4.7 | 1.4.7 |
Affected products
9cpe:2.3:a:toni_mueller:roundup:1.2.0:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:toni_mueller:roundup:1.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:toni_mueller:roundup:1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:toni_mueller:roundup:1.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:toni_mueller:roundup:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:toni_mueller:roundup:1.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:toni_mueller:roundup:1.4.4:*:*:*:*:*:*:*
- cpe:2.3:a:toni_mueller:roundup:1.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:toni_mueller:roundup:1.4.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- www.debian.org/security/2009/dsa-1754nvdPatchWEB
- secunia.com/advisories/34192nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-9rj9-5wcv-xgf2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2009-2737ghsaADVISORY
- bugs.debian.org/cgi-bin/bugreport.cginvdWEB
- issues.roundup-tracker.org/issue2550521nvdWEB
- www.osvdb.org/56368nvdWEB
- www.securityfocus.com/bid/34059nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/roundup-tracker/roundup/blob/d24abceaa19072b28e5c8ae0db4dd341597d14fc/CHANGES.txtghsaWEB
- sourceforge.net/p/roundup/code/ci/4081ghsaWEB
- www.redhat.com/archives/fedora-package-announce/2009-March/msg00429.htmlnvdWEB
- www.redhat.com/archives/fedora-package-announce/2009-March/msg00439.htmlnvdWEB
News mentions
0No linked articles in our index yet.