1.6.1
7 years ago
15 days ago
Known vulnerabilities in the docassemble package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
docassemble is an A free, open-source expert system for guided interviews and document assembly, based on Python, YAML, and Markdown. Affected versions of this package are vulnerable to Open Redirect due to improper validation of user-supplied input. An attacker can redirect users to an untrusted page by manipulating the URL parameters to point to a malicious site. How to fix Open Redirect? Upgrade | [,1.4.97) |
docassemble is an A free, open-source expert system for guided interviews and document assembly, based on Python, YAML, and Markdown. Affected versions of this package are vulnerable to Access Restriction Bypass. This allows attackers to gain unauthorized access to information on the system through URL manipulation. How to fix Access Restriction Bypass? Upgrade | [,1.2.65) |