Improper Access Control Affecting docassemble.base package, versions [1.4.53,1.4.97)


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
0.08% (38th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Access Control vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-DOCASSEMBLEBASE-6347251
  • published1 Mar 2024
  • disclosed29 Feb 2024
  • creditRiyush Ghimire

Introduced: 29 Feb 2024

CVE-2024-27292  (opens in a new tab)
CWE-284  (opens in a new tab)

How to fix?

Upgrade docassemble.base to version 1.4.97 or higher.

Overview

docassemble.base is a The base components of the docassemble system.

Affected versions of this package are vulnerable to Improper Access Control due to improper validation of user-supplied input through URL parameters. An attacker can gain unauthorized access to information on the system by manipulating URLs to bypass access controls.

Workaround

This vulnerability can be mitigated by manually applying the changes of 97f77dc and restarting the server.

CVSS Scores

version 3.1