Access Control Bypass Affecting docksible package, versions [,0.6.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Access Control Bypass vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-DOCKSIBLE-8445301
  • published2 Dec 2024
  • disclosed1 Dec 2024
  • creditUnknown

Introduced: 1 Dec 2024

New CVE NOT AVAILABLE CWE-284  (opens in a new tab)

How to fix?

Upgrade docksible to version 0.6.1 or higher.

Overview

docksible is a Deploy and set up Docker Compose based web apps with Ansible

Affected versions of this package are vulnerable to Access Control Bypass. This vulnerability allows attackers to exploit the /xmlrpc.php endpoint in WordPress, enabling brute force attacks, DDoS attacks, and potential remote code execution. The issue arises from unrestricted access to /xmlrpc.php in the Nginx configuration files. It is exploitable remotely by sending crafted HTTP requests to the endpoint.

References

CVSS Scores

version 4.0
version 3.1