Authorization Bypass Affecting acryl-datahub package, versions [,0.8.45)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.07% (32nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Authorization Bypass vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-ACRYLDATAHUB-6241909
  • published12 Feb 2024
  • disclosed1 Feb 2024
  • creditAlvaro Muñoz, Peter Stöckli, Kevin Stubbings, Sylwia Budzynska, Michael Stepankin, Jorge

Introduced: 1 Feb 2024

CVE-2023-25559  (opens in a new tab)
CWE-285  (opens in a new tab)

How to fix?

Upgrade acryl-datahub to version 0.8.45 or higher.

Overview

acryl-datahub is an A CLI to work with DataHub metadata

Affected versions of this package are vulnerable to Authorization Bypass due to the X-DataHub-Actor HTTP header improperly identifying the user making requests without authentication. This can be exploited by attackers who can manipulate the case of the header, leading to potential and unauthorized actions.

CVSS Base Scores

version 3.1