CVE-2024-35184
CVSS V2 None
CVSS V3 None
Description
Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is explicitly disabled. Version 2.8.6 contains a patchc for the issue.
Overview
- CVE ID
- CVE-2024-35184
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-05-15T21:29:33.712Z
- Last Modified Date
- 2024-06-04T17:34:14.009Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/paperless-ngx/paperless-ngx/security/advisories/GHSA-72w4-hxqq-c256 | x_refsource_CONFIRM |
https://github.com/paperless-ngx/paperless-ngx/pull/6739 | x_refsource_MISC |
https://github.com/paperless-ngx/paperless-ngx/commit/ed05b40ba461641b1b59b0a92f51f3f6a66ce180 | x_refsource_MISC |
https://github.com/paperless-ngx/paperless-ngx/releases/tag/v2.8.6 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-35184 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35184 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 13:59:28 | Added to TrackCVE |