Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-21644
HistoryJan 08, 2024 - 2:15 p.m.

Design/Logic Flaw

2024-01-0814:15:00
PRIOn knowledge base
www.prio-n.com
2
pyload download manager
design flaw
logic flaw
patched
version 0.5.0b3.dev77
nvd
unauthenticated user
flask config
secret_key exposure

7.2 High

AI Score

Confidence

Low

0.118 Low

EPSS

Percentile

95.3%

pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the SECRET_KEY variable. This issue has been patched in version 0.5.0b3.dev77.

7.2 High

AI Score

Confidence

Low

0.118 Low

EPSS

Percentile

95.3%