{"id":"GHSA-qrmm-w4v4-q7f8","aliases":[],"url":"https://o3.security/vulnerability/GHSA-qrmm-w4v4-q7f8","summary":"Unauthorized access through URL manipulation","details":"### Impact\nThe vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation.\n\n### Patches\nThe vulnerability has been patched in version 1.2.65 of the `master` branch, version 1.1.113 of the 1.1.x series, and version 1.0.12 of the `stable` branch. The Docker image on docker.io has been patched.\n\n### Workarounds\nIf upgrading is not possible, manually apply the changes of https://github.com/jhpyle/docassemble/commit/e3dbf6ce054b3c0310996f0657289f5eed0a73fe and restart the server (e.g., by pressing Save on the Configuration screen).\n\n### Credit\nThe vulnerability was discovered by Jim Platania of Seiso LLC (@jimmio).\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [docassemble](https://github.com/jhpyle/docassemble/issues)\n* Join the [Slack channel](https://join.slack.com/t/docassemble/shared_invite/zt-ohrn8y9z-_Fb3RAl~JPBU6Km7odBPfQ)\n* Email us at [jhpyle@gmail.com](mailto:jhpyle@gmail.com)\n","published":"2021-05-06T15:27:22Z","modified":"2024-12-02T05:43:23.440188Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"docassemble","fixedVersion":"1.2.65"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/jhpyle/docassemble/security/advisories/GHSA-qrmm-w4v4-q7f8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:43:23.440188Z"}}