Skip to content

File Permissions can by bypassed using certain endpoints

High
ankush published GHSA-hq5v-q29v-7rcw Mar 20, 2024

Package

frappe (frappe)

Affected versions

<15.16.0
<14.66.3

Patched versions

15.16.0
14.66.3

Description

Impact

What kind of vulnerability is it? Who is impacted?
File permission can be bypassed using certain endpoints, granting less privileged user permission to delete or clone a file.

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?
There is no workaround, upgrading to latest version is required to receive the fix.

References

Are there any links users can visit to find out more?

Severity

High
8.1
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CVE ID

CVE-2024-27105

Weaknesses

No CWEs

Credits