docassemble@1.1.105 vulnerabilities

The namespace package for the docassemble system.

Direct Vulnerabilities

Known vulnerabilities in the docassemble package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Open Redirect

docassemble is an A free, open-source expert system for guided interviews and document assembly, based on Python, YAML, and Markdown.

Affected versions of this package are vulnerable to Open Redirect due to improper validation of user-supplied input. An attacker can redirect users to an untrusted page by manipulating the URL parameters to point to a malicious site.

How to fix Open Redirect?

Upgrade docassemble to version 1.4.97 or higher.

[,1.4.97)
  • H
Access Restriction Bypass

docassemble is an A free, open-source expert system for guided interviews and document assembly, based on Python, YAML, and Markdown.

Affected versions of this package are vulnerable to Access Restriction Bypass. This allows attackers to gain unauthorized access to information on the system through URL manipulation.

How to fix Access Restriction Bypass?

Upgrade docassemble to version 1.2.65 or higher.

[,1.2.65)