Safety vulnerability ID: 54473
The information on this page was manually curated by our Cybersecurity Intelligence Team.
rdiffweb prior to 2.4.3 is vulnerable to Cross-Site Request Forgery (CSRF). While adding SSH public keys to the profile, the server accepts the GET request, which results in adding an SSH public key to the profile and leads to unauthorized access to the system and backups. Version 2.4.3 contains a patch for this issue.
Latest version: 2.9.5
A web interface to rdiff-backup repositories.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application