CVE-2014-6275: Debian Linux
Medium severity, CVSS 5.9. EPSS: 0.9% chance of exploitation in the next 30 days.
FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages are hosted on the same server than FusionForge, it can allow users to incorrectly access on-disk private data in FusionForge.
Affected products
- Debian Debian Linux: version 8.0 only
- Fusionforge Fusionforge: before 5.3.2 (fixed in 5.3.2)
Published 2020-01-02. Last modified 2026-06-17.