viur-core@3.5.0b1 vulnerabilities

The core component of ViUR, a development framework for Google App Engine

  • latest version

    3.7.6

  • latest non vulnerable version

  • first published

    2 years ago

  • latest version published

    5 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the viur-core package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Access Control Bypass

    viur-core is a The core component of ViUR, a development framework for Google App Engine

    Affected versions of this package are vulnerable to Access Control Bypass due to data being inadvertently rendered through the default view.html template. This could lead to unauthorized data exposure.

    How to fix Access Control Bypass?

    Upgrade viur-core to version 3.6.0rc1 or higher.

    [,3.6.0rc1)