Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://huntr.dev/bounties/02207c8f-2b15-4a31-a86a-74fd2fca0ed1 | third party advisory permissions required |
https://github.com/ikus060/rdiffweb/commit/f2a32f2a9f3fb8be1a9432ac3d81d3aacdb13095 | third party advisory patch |
https://huntr.com/bounties/02207c8f-2b15-4a31-a86a-74fd2fca0ed1 |