Lucene search

K
nvd[email protected]NVD:CVE-2024-21644
HistoryJan 08, 2024 - 2:15 p.m.

CVE-2024-21644

2024-01-0814:15:47
CWE-284
web.nvd.nist.gov
pyload
download manager
secret key
flask config
unauthenticated user
patched
version 0.5.0b3.dev77

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.118 Low

EPSS

Percentile

95.3%

pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the SECRET_KEY variable. This issue has been patched in version 0.5.0b3.dev77.

Affected configurations

NVD
Node
pyloadpyloadRange0.4.9
OR
pyloadpyloadMatch0.5.0beta1
OR
pyloadpyloadMatch0.5.0beta2

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.118 Low

EPSS

Percentile

95.3%