Safety vulnerability ID: 66714
The information on this page was manually curated by our Cybersecurity Intelligence Team.
kinto-attachment versions above 6.4.0 are susceptible to a vulnerability where an attachment file on an existing record can be replaced by users who possess "read" permission on any of the parent entities, such as a collection or bucket. Should this "read" permission be granted to "system.Everyone" on one of the parents, it enables the replacement of an attachment on a record through an anonymous request. Importantly, should the parent entities not have explicit "read" permission assigned, the attachments on records remain secure against such unauthorized replacements.
Latest version: 7.0.0
Attach files to Kinto records
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application