freetakserver@1.9.8.5 vulnerabilities

An open source server for the TAK family of applications.

  • latest version

    2.2.1

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    10 months ago

  • licenses detected

    • [0.1.7.3,0.1.9.9.5.5); [1.5.10,1.9.9.3)
  • Direct Vulnerabilities

    Known vulnerabilities in the freetakserver package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    FreeTAKServer is an An open source server for the TAK family of applications.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization, via the addSysteUser , file_hash, read_yaml_config methods and username parameter.

    How to fix Cross-site Scripting (XSS)?

    Upgrade FreeTAKServer to version 2.0.21 or higher.

    [,2.0.21)
    • H
    Improper Access Control

    FreeTAKServer is an An open source server for the TAK family of applications.

    Affected versions of this package are vulnerable to Improper Access Control in the component /ManageRoute/postRoute which allows unauthenticated attackers to cause a Denial of Service via an unusually large amount of created routes, or create unsafe or false routes for legitimate users.

    How to fix Improper Access Control?

    Upgrade FreeTAKServer to version 1.9.8.6 or higher.

    [0,1.9.8.6)