Vulnerability Description
Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jhpyle | Docassemble | >= 1.4.53, < 1.4.97 |
Related Weaknesses (CWE)
References
- https://github.com/jhpyle/docassemble/commit/97f77dc486a26a22ba804765bfd7058aabdPatch
- https://github.com/jhpyle/docassemble/security/advisories/GHSA-jq57-3w7p-vwvvThird Party Advisory
- https://github.com/jhpyle/docassemble/commit/97f77dc486a26a22ba804765bfd7058aabdPatch
- https://github.com/jhpyle/docassemble/security/advisories/GHSA-jq57-3w7p-vwvvThird Party Advisory
FAQ
What is CVE-2024-27292?
CVE-2024-27292 is a vulnerability with a CVSS score of 7.5 (HIGH). Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It af...
How severe is CVE-2024-27292?
CVE-2024-27292 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-27292?
Check the references section above for vendor advisories and patch information. Affected products include: Jhpyle Docassemble.