Information Disclosure Affecting frappe package, versions [11.0.0,11.1.64)[12.0.0,12.1.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.15% (52nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-FRAPPE-560764
  • published18 Mar 2020
  • disclosed18 Mar 2020
  • creditUnknown

Introduced: 18 Mar 2020

CVE-2019-20529  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade frappe to version 11.1.64, 12.1.0 or higher.

Overview

frappe is a Low Code Open Source Framework in Python and JS.

Affected versions of this package are vulnerable to Information Disclosure. In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files.

CVSS Scores

version 3.1