PT-2021-24453 · Unknown · Docassemble
Published
2021-05-06
·
Updated
2021-05-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions:
docassemble versions prior to 1.2.65
docassemble versions prior to 1.1.113
docassemble versions prior to 1.0.12
Description:
The issue allows attackers to gain unauthorized access to system information through URL manipulation. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations:
For versions prior to 1.2.65, update to version 1.2.65 or later.
For versions prior to 1.1.113, update to version 1.1.113 or later.
For versions prior to 1.0.12, update to version 1.0.12 or later.
As a temporary workaround, manually apply the changes from https://github.com/jhpyle/docassemble/commit/e3dbf6ce054b3c0310996f0657289f5eed0a73fe and restart the server.
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docassemble