CVE-2024-27105

CVSS V2 None CVSS V3 None
Description
Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed using certain endpoints, granting less privileged users permission to delete or clone a file. Versions 14.66.3 and 15.16.0 contain a patch for this issue. No known workarounds are available.
Overview
  • CVE ID
  • CVE-2024-27105
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-03-20T18:11:58.069Z
  • Last Modified Date
  • 2024-03-20T18:11:58.069Z
References
Reference URL Reference Tags
https://github.com/frappe/frappe/security/advisories/GHSA-hq5v-q29v-7rcw x_refsource_CONFIRM
History
Created Old Value New Value Data Type Notes
2024-06-26 02:11:09 Added to TrackCVE