Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x24j-87x9-jvv5

Опубликовано: 03 нояб. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Publify guest role users can self-register even when the admin does not allow it

In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. guest role users can self-register even when the admin does not allow it. This happens due to front-end restriction only.

Пакеты

Наименование

publify_core

rubygems
Затронутые версииВерсия исправления

>= 9.0.0.pre1, < 9.2.5

9.2.5

EPSS

Процентиль: 37%
0.00157
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285
CWE-669
CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
больше 4 лет назад

In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only.

EPSS

Процентиль: 37%
0.00157
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285
CWE-669
CWE-863