VYPR
High severityNVD Advisory· Published Feb 16, 2015· Updated May 6, 2026

CVE-2015-0260

CVE-2015-0260

Description

RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
RhodeCodePyPI
< 2.2.72.2.7
KallitheaPyPI
< 0.20.2

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

12

News mentions

0

No linked articles in our index yet.