bepasty@0.1.0 vulnerabilities

a binary pastebin / file upload service

  • latest version

    1.2.1

  • latest non vulnerable version

  • first published

    10 years ago

  • latest version published

    9 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the bepasty package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Improper Validation

    Affected versions of this package are vulnerable to Improper Validation. It does not invalidates old client-side cookies if PERMISSIONS in config are changed.

    How to fix Improper Validation?

    Upgrade bepasty to version 0.6.0 or higher.

    [,0.6.0)
    • M
    Information Exposure

    bepasty is a binary pastebin / file upload service Affected versions of this package are vulnerable to Information Exposure. The metadata of locked files is visible for users with the read permission.

    [,0.3.0)
    • M
    Cross-site Scripting (XSS)

    bepasty is a binary pastebin / file upload service.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) attacks via the download.py file, due to it rendering the content as html rather text. An attacker user could craft a file that would run on the server and execute arbitrary code.

    [,0.3.0)