Rhodecode is a source-code management and collaboration platform deployed in development and operations environments, with its vulnerability profile centered on the Rhodecode Enterprise product. The observed weakness classes point toward information-disclosure risks in authentication and repository-access handling, reflecting the sensitive nature of source-code repositories as attack targets. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rhodecode over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-0260MEDIUM RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method. | Feb 16, 2015 | 4.0 | 17 | NO | NO |
CVE-2015-1613MEDIUM RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API metho | Feb 16, 2015 | 4.0 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rhodecode.
Media articles that mention a CVE ID that affects a product developed by Rhodecode — matched by CVE ID, not by vendor name.