Access Restriction Bypass Affecting formencode package, versions [,1.0.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.71% (72nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Access Restriction Bypass vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-FORMENCODE-40737
  • published4 Dec 2017
  • disclosed30 Mar 2009
  • creditPetter Urkedal

Introduced: 30 Mar 2009

CVE-2008-6547  (opens in a new tab)
CWE-284  (opens in a new tab)

How to fix?

Upgrade formencode to version 1.0.1 or higher.

Overview

Affected versions of formencode are vulnerable to Access Restriction Bypass

schema.py in FormEncode for Python (python-formencode) 1.0 does not apply the chained_validators feature, which allows attackers to bypass intended access restrictions via unknown vectors.

References

CVSS Base Scores

version 3.1