EVE-SRP@0.12.11 vulnerabilities

EVE Ship Replacement Program Helper

Direct Vulnerabilities

Known vulnerabilities in the EVE-SRP package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Information Exposure

EVE-SRP is an EVE Ship Replacement Program (SRP) webapp

Affected versions of this package are vulnerable to Information Exposure in the user_detail()and group_detail() function in src/evesrp/views/api.py, accessible via the /api/user/<id> or /api/group/<id> route. An unauthorized user can view user and group details as well as previous SRP requests.

How to fix Information Exposure?

A fix was pushed into the master branch but not yet published.

[0,)