Security Advisory
CVE-2005-4854
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
eZ publish 3.5 through 3.7 before 20050830 does not use a folders read permissions to restrict notifications, which allows remote authenticated users to obtain sensitive information about changes to content in arbitrary folders.