Improper authorization control for web services In rdiffweb
Description
rdiffweb vulnerable to Authentication Bypass by Primary Weakness In rdiffweb prior to 2.5.5, the username field is not unique to users. This allows exploitation of primary key logic by creating the same name with different combinations & may allow unauthorized access.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 2.5.5 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.