PT-2024-37073 · Simofa · Simofa

Truewinter

·

Published

2024-12-30

·

Updated

2025-01-04

·

CVE-2024-56799

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Simofa versions prior to 0.2.7
Description Simofa is a tool to help automate static website building and deployment. Due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication.
Recommendations For versions prior to 0.2.7, upgrade to version 0.2.7 to resolve the issue. As a temporary workaround, consider restricting access to sensitive API routes until the upgrade is applied.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-56799
GHSA-83QW-5QQ5-V7PQ

Affected Products

Simofa