Clickjacking Affecting doccano package, versions [0,1.0.1)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-DOCCANO-1910239
- published 3 Nov 2021
- disclosed 3 Nov 2021
- credit Unknown
How to fix?
Upgrade doccano
to version 1.0.1 or higher.
Overview
doccano is a text annotation tool for machine learning practitioners.
Affected versions of this package are vulnerable to Clickjacking via the X-Frame-Options
header which is disabled.
References
CVSS Scores
version 3.1