eve-srp@0.10.5 vulnerabilities

EVE Ship Replacement Program Helper

Direct Vulnerabilities

Known vulnerabilities in the eve-srp package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Information Exposure

EVE-SRP is an EVE Ship Replacement Program (SRP) webapp

Affected versions of this package are vulnerable to Information Exposure in the user_detail()and group_detail() function in src/evesrp/views/api.py, accessible via the /api/user/<id> or /api/group/<id> route. An unauthorized user can view user and group details as well as previous SRP requests.

How to fix Information Exposure?

A fix was pushed into the master branch but not yet published.

[0,)