PyPi: Kinto-Attachment

CVE-2024-1314

Safety vulnerability ID: 66714

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Mar 15, 2024 Updated at Mar 15, 2024
Scan your Python projects for vulnerabilities →

Advisory

kinto-attachment versions above 6.4.0 are susceptible to a vulnerability where an attachment file on an existing record can be replaced by users who possess "read" permission on any of the parent entities, such as a collection or bucket. Should this "read" permission be granted to "system.Everyone" on one of the parents, it enables the replacement of an attachment on a record through an anonymous request. Importantly, should the parent entities not have explicit "read" permission assigned, the attachments on records remain secure against such unauthorized replacements.

Affected package

kinto-attachment

Latest version: 6.4.0

Attach files to Kinto records

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application