docassemble@1.2.85 vulnerabilities

The namespace package for the docassemble system.

  • latest version

    1.6.1

  • latest non vulnerable version

  • first published

    7 years ago

  • latest version published

    15 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the docassemble package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Open Redirect

    docassemble is an A free, open-source expert system for guided interviews and document assembly, based on Python, YAML, and Markdown.

    Affected versions of this package are vulnerable to Open Redirect due to improper validation of user-supplied input. An attacker can redirect users to an untrusted page by manipulating the URL parameters to point to a malicious site.

    How to fix Open Redirect?

    Upgrade docassemble to version 1.4.97 or higher.

    [,1.4.97)