Описание
FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed should be viewable if anonymous viewing is enabled, and feeds of other users should be private. This vulnerability is fixed in 1.28.0.
Ссылки
- Patch
- Issue TrackingPatch
- ProductRelease Notes
- ExploitPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.28.0 (исключая)
cpe:2.3:a:freshrss:freshrss:*:*:*:*:*:*:*:*
EPSS
Процентиль: 31%
0.0038
Низкий
7.5 High
CVSS3
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 7.5
debian
6 месяцев назад
FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug ...
EPSS
Процентиль: 31%
0.0038
Низкий
7.5 High
CVSS3
Дефекты
CWE-284