PT-2026-61043 · Gerapy · Gerapy
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Gerapy versions prior to 0.9.14
Description
An issue in the Project Upload Endpoint within the
gerapy/server/core/views.py file allows remote attackers to bypass authentication. This missing authentication enables unauthenticated remote access to the system.Recommendations
Apply patch bd4891c60315f17611a3b7a651ffe0fba7cfe71e to resolve the issue.
Restrict access to the Project Upload Endpoint to minimize the risk of exploitation.
Exploit
Fix
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gerapy