CVE-2008-4215

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
10/10/2008
Last modified:
09/04/2025

Description

Weblog in Mac OS X Server 10.4.11 does not properly check an error condition when a weblog posting access control list is specified for a user that has multiple short names, which might allow attackers to bypass intended access restrictions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*