Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hvp4-vrv2-8wrq

Опубликовано: 08 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

Kinto Attachment's attachments can be replaced on read-only records

Impact

The attachment file of an existing record can be replaced if the user has "read" permission on one of the parent (collection or bucket).

And if the "read" permission is given to "system.Everyone" on one of the parent, then the attachment can be replaced on a record using an anonymous request.

Note that if the parent has no explicit read permission, then the records attachments are safe.

Patches

Workarounds

None if the read permission has to remain granted.

Updating to 6.4.0 or applying the patch individually (if updating is not feasible) is strongly recommended.

References

Пакеты

Наименование

kinto-attachment

pip
Затронутые версииВерсия исправления

<= 6.3.2

6.4.0

8.6 High

CVSS3

8.6 High

CVSS3