viur-core@3.1.4 vulnerabilities

The core component of ViUR, a development framework for Google App Engine

Direct Vulnerabilities

Known vulnerabilities in the viur-core package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Access Control Bypass

viur-core is a The core component of ViUR, a development framework for Google App Engine

Affected versions of this package are vulnerable to Access Control Bypass due to data being inadvertently rendered through the default view.html template. This could lead to unauthorized data exposure.

How to fix Access Control Bypass?

Upgrade viur-core to version 3.6.0rc1 or higher.

[,3.6.0rc1)
  • M
Access Restriction Bypass

viur-core is a The core component of ViUR, a development framework for Google App Engine

Affected versions of this package are vulnerable to Access Restriction Bypass when using custom login handlers users were able to authenticate even when they were disabled by the system.

How to fix Access Restriction Bypass?

Upgrade viur-core to version 3.4.0rc2 or higher.

[,3.4.0rc2)