Information Exposure Affecting eve-srp package, versions [0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.07% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-EVESRP-3312073
  • published7 Feb 2023
  • disclosed7 Feb 2023
  • creditUnknown

Introduced: 7 Feb 2023

CVE-2020-36660  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

EVE-SRP is an EVE Ship Replacement Program (SRP) webapp

Affected versions of this package are vulnerable to Information Exposure in the user_detail()and group_detail() function in src/evesrp/views/api.py, accessible via the /api/user/<id> or /api/group/<id> route. An unauthorized user can view user and group details as well as previous SRP requests.

CVSS Scores

version 3.1