PT-2021-24453 · Unknown · Docassemble

Published

2021-05-06

·

Updated

2021-05-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: docassemble versions prior to 1.2.65 docassemble versions prior to 1.1.113 docassemble versions prior to 1.0.12
Description: The issue allows attackers to gain unauthorized access to system information through URL manipulation. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations: For versions prior to 1.2.65, update to version 1.2.65 or later. For versions prior to 1.1.113, update to version 1.1.113 or later. For versions prior to 1.0.12, update to version 1.0.12 or later. As a temporary workaround, manually apply the changes from https://github.com/jhpyle/docassemble/commit/e3dbf6ce054b3c0310996f0657289f5eed0a73fe and restart the server.

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-QRMM-W4V4-Q7F8

Affected Products

Docassemble