Описание
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.
EPSS
Процентиль: 22%
0.00293
Низкий
8.6 High
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 8.6
github
6 дней назад
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.
EPSS
Процентиль: 22%
0.00293
Низкий
8.6 High
CVSS3
Дефекты
CWE-862