Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5.
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
Link | Tags |
---|---|
https://huntr.dev/bounties/428eee94-f1a0-45d0-9e25-318641115550 | exploit third party advisory patch |
https://github.com/bookwyrm-social/bookwyrm/commit/7bbe42fb30a79a26115524d18b697d895563c92f | third party advisory patch |
http://packetstormsecurity.com/files/168423/Bookwyrm-0.4.3-Authentication-Bypass.html | exploit vdb entry third party advisory |