MEDIUM
Improper Authorization in wallabag/wallabag
Published Feb 1, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.64%
Description
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
Affected products
-
Affected
- ≥ unspecified, < 2.5.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Wallabag | Wallabag/wallabag | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0779 Advisory
- https://github.com/advisories/GHSA-qwx8-mxxx-mg96 Advisory
- https://github.com/wallabag/wallabag/commit/0f7460dbab9e29f4f7d2944aca20210f828b6abb PatchVendor Advisory
- https://github.com/wallabag/wallabag/security/advisories/GHSA-qwx8-mxxx-mg96
- https://huntr.dev/bounties/3adef66f-fc86-4e6d-a540-2ffa59342ff0 ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-0609
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Feb 1, 2023
Updated Mar 26, 2025
Reserved Feb 1, 2023
Link CVE-2023-0609
CISA Vulnrichment
Updated Mar 26, 2025
Red Hat
No data
GitHub
Link GHSA-QWX8-MXXX-MG96