Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mv7x-27pc-8c96

Опубликовано: 30 мая 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Go package pydio/cells vulnerable to authorization bypass

A vulnerability was found in Abstrium Pydio Cells 4.2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Change Subscription Handler. The manipulation leads to authorization bypass. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. VDB-230210 is the identifier assigned to this vulnerability.

Пакеты

Наименование

github.com/pydio/cells

go
Затронутые версииВерсия исправления

< 4.2.1

4.2.1

EPSS

Процентиль: 9%
0.00033
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 4.6
nvd
больше 2 лет назад

A vulnerability was found in Abstrium Pydio Cells 4.2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Change Subscription Handler. The manipulation leads to authorization bypass. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. VDB-230210 is the identifier assigned to this vulnerability.

EPSS

Процентиль: 9%
0.00033
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-639