Safety vulnerability ID: 78814
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of the codechecker package are vulnerable to Authentication Bypass due to improper URL path validation in the API endpoint handling. The vulnerability occurs when API URLs end with specific strings like "Authentication", "Configuration", or "ServerInfo", which causes the authentication mechanism to be bypassed and grants superuser privileges to all API endpoints except the Authentication endpoint itself. An unauthenticated remote attacker can exploit this vulnerability by crafting API requests with valid CodeChecker endpoints that terminate with these specific strings, allowing them to query, add, modify, or delete products on the CodeChecker server without any authentication.
Latest version: 6.26.0
CodeChecker is an analyzer tooling, defect database and viewer extension
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application