Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j27j-25gc-gv9v

Опубликовано: 15 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization bearer value as a userId and enters a non-terminating body-handling branch for any non-empty bearer token, enabling trivial application-layer DoS and latent identity-spoofing.

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization bearer value as a userId and enters a non-terminating body-handling branch for any non-empty bearer token, enabling trivial application-layer DoS and latent identity-spoofing.

EPSS

Процентиль: 19%
0.00061
Низкий

8.2 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.2
nvd
около 2 месяцев назад

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization bearer value as a userId and enters a non-terminating body-handling branch for any non-empty bearer token, enabling trivial application-layer DoS and latent identity-spoofing.

EPSS

Процентиль: 19%
0.00061
Низкий

8.2 High

CVSS3

Дефекты

CWE-287