CVE-2024-27292High· 7.5▾ MidnightPoC availableDocassemble unauthorized access through URL manipulation
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 13.9 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
69%
2 GitHub repos · Nuclei ×1
Last analysed / modified upstream
The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96.
The vulnerability has been patched in version 1.4.97 of the master branch. The Docker image on docker.io has been patched.
If upgrading is not possible, manually apply the changes of 97f77dc and restart the server.
The vulnerability was discovered by Riyush Ghimire (@richighimi).
If you have any questions or comments about this advisory:
docassemble-webapp >= 1.4.53, < 1.4.97docassemble-base >= 1.4.53, < 1.4.97Upgrade to a patched release:
docassemble-webapp 1.4.97docassemble-base 1.4.97Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.