In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Missing Authorization vulnerabilities in an interactive lesson.
Start learningUpgrade anitya to version 2.3.0 or higher.
anitya is an A cross-distribution upstream release monitoring project
Affected versions of this package are vulnerable to Missing Authorization via the delete_user process. An attacker can remove arbitrary user accounts, including those with administrative privileges, by sending crafted requests after authentication. This can result in loss of administrative access and potential disruption of service.
This vulnerability can be mitigated by blocking the URL path pattern /users/*/delete at the reverse proxy (such as Apache or nginx) until a patch is available. Note that this will also prevent administrators from deleting users through the web UI; such operations would need to be performed directly in the database if required.