Skip to content

Public pages acessibility restriction

High
trasher published GHSA-jrqg-mpwv-pxpv Mar 6, 2024

Package

Galette

Affected versions

1.0.0, 1.0.1

Patched versions

1.0.2

Description

Public pages are per default restricted to only administrators and staff members. From configuration, it is possible to restrict to up-to-date members or to everyone.

Severity

High
7.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE ID

CVE-2024-24761

Weaknesses

No CWEs

Credits