Access Restriction Bypass
Affecting products.pluggableauthservice package, versions [,2.6.2)
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
Products.PluggableAuthService is a Pluggable Zope authentication / authorization framework
Affected versions of this package are vulnerable to Access Restriction Bypass. Multiple login string transformation methods are set to public which could lead to Access Control issues. The vulnerability is likely not exploitable.
Remediation
Upgrade Products.PluggableAuthService
to version 2.6.2 or higher.
References
CVSS Score
3.7
low severity
-
Attack VectorNetwork
-
Attack ComplexityHigh
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityLow
-
IntegrityNone
-
AvailabilityNone
- Credit
- Unknown
- CWE
- CWE-284
- Snyk ID
- SNYK-PYTHON-PRODUCTSPLUGGABLEAUTHSERVICE-1090197
- Disclosed
- 01 Apr, 2021
- Published
- 01 Apr, 2021