Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Advisories: GSA_kwCzR0hTQS03bWM0LWpwNGYtdjJqMs4AAw-x
Improper Authorization in grumpydictator/firefly-iii
Improper Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0.
Permalink: https://github.com/advisories/GHSA-7mc4-jp4f-v2j2Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 22 days ago
Updated: 10 days ago
CVSS Score: 6.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Identifiers: GHSA-7mc4-jp4f-v2j2, CVE-2023-0298
References:
- https://nvd.nist.gov/vuln/detail/CVE-2023-0298
- https://github.com/firefly-iii/firefly-iii/commit/db0500dcf0d4f1990fc7a377ef0d56c3884fcaa4
- https://huntr.dev/bounties/9689052c-c1d7-4aae-aa08-346c9b6e04ed
- https://github.com/advisories/GHSA-7mc4-jp4f-v2j2
Affected Packages
packagist:grumpydictator/firefly-iii
Versions: < 5.8.0Fixed in: 5.8.0