papermerge-core@2.0.2 vulnerabilities

Open source document management system for digital archives

  • latest version

    2.1.5

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    1 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the papermerge-core package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Authorization Bypass Through User-Controlled Key

    papermerge-core is an Open source document management system designed for scanned documents

    Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via document-versions/uuid:pk/download/ API by allowing any user to download any file.

    How to fix Authorization Bypass Through User-Controlled Key?

    Upgrade papermerge-core to version 2.1.0b7 or higher.

    [,2.1.0b7)