GHSA-jq57-3w7p-vwvv

Suggest an improvement
Source
https://github.com/advisories/GHSA-jq57-3w7p-vwvv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-jq57-3w7p-vwvv/GHSA-jq57-3w7p-vwvv.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-jq57-3w7p-vwvv
Aliases
Published
2024-02-29T22:14:46Z
Modified
2024-03-21T18:33:05.127420Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Docassemble unauthorized access through URL manipulation
Details

Impact

The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96.

Patches

The vulnerability has been patched in version 1.4.97 of the master branch. The Docker image on docker.io has been patched.

Workarounds

If upgrading is not possible, manually apply the changes of 97f77dc and restart the server.

Credit

The vulnerability was discovered by Riyush Ghimire (@richighimi).

For more information

If you have any questions or comments about this advisory:

Database specific
{
    "nvd_published_at": "2024-03-21T02:52:19Z",
    "cwe_ids": [
        "CWE-706"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-02-29T22:14:46Z"
}
References

Affected packages

PyPI / docassemble-webapp

Package

Name
docassemble-webapp
View open source insights on deps.dev
Purl
pkg:pypi/docassemble-webapp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.4.53
Fixed
1.4.97

Affected versions

1.*

1.4.53
1.4.54
1.4.55
1.4.56
1.4.57
1.4.58
1.4.59
1.4.60
1.4.61
1.4.62
1.4.63
1.4.64
1.4.65
1.4.66
1.4.67
1.4.68
1.4.69
1.4.70
1.4.71
1.4.72
1.4.73
1.4.74
1.4.75
1.4.76
1.4.77
1.4.78
1.4.79
1.4.80
1.4.81
1.4.82
1.4.83
1.4.84
1.4.85
1.4.86
1.4.87
1.4.88
1.4.89
1.4.90
1.4.91
1.4.92
1.4.93
1.4.94
1.4.95
1.4.96

PyPI / docassemble-base

Package

Name
docassemble-base
View open source insights on deps.dev
Purl
pkg:pypi/docassemble-base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.4.53
Fixed
1.4.97

Affected versions

1.*

1.4.53
1.4.54
1.4.55
1.4.56
1.4.57
1.4.58
1.4.59
1.4.60
1.4.61
1.4.62
1.4.63
1.4.64
1.4.65
1.4.66
1.4.67
1.4.68
1.4.69
1.4.70
1.4.71
1.4.72
1.4.73
1.4.74
1.4.75
1.4.76
1.4.77
1.4.78
1.4.79
1.4.80
1.4.81
1.4.82
1.4.83
1.4.84
1.4.85
1.4.86
1.4.87
1.4.88
1.4.89
1.4.90
1.4.91
1.4.92
1.4.93
1.4.94
1.4.95
1.4.96