Vulnerability Description
pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This issue has been patched in version 0.5.0b3.dev77.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pyload | Pyload | <= 0.4.9 |
Related Weaknesses (CWE)
References
- https://github.com/pyload/pyload/commit/bb22063a875ffeca357aaf6e2edcd09705688c40Patch
- https://github.com/pyload/pyload/security/advisories/GHSA-mqpq-2p68-46fvExploitVendor Advisory
- https://github.com/pyload/pyload/commit/bb22063a875ffeca357aaf6e2edcd09705688c40Patch
- https://github.com/pyload/pyload/security/advisories/GHSA-mqpq-2p68-46fvExploitVendor Advisory
FAQ
What is CVE-2024-21644?
CVE-2024-21644 is a vulnerability with a CVSS score of 7.5 (HIGH). pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This ...
How severe is CVE-2024-21644?
CVE-2024-21644 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-21644?
Check the references section above for vendor advisories and patch information. Affected products include: Pyload Pyload.