Information Exposure Affecting rucio-webui package, versions [1.26.0,1.26.7)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-RUCIOWEBUI-5498642
  • published8 May 2023
  • disclosed8 May 2023
  • creditMartin Barisits

Introduced: 8 May 2023

CVE NOT AVAILABLE CWE-200  (opens in a new tab)

How to fix?

Upgrade rucio-webui to version 1.26.7 or higher.

Overview

Affected versions of this package are vulnerable to Information Exposure such that authentication tokens are leaked to other users accessing the 'webui' within a close timeframe, thus allowing users to access the webui with the leaked authentication token. Privileges are therefore also escalated.

Note: Rucio server / daemons are not affected by this issue.

CVSS Base Scores

version 3.1