THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2024-35184

paperless-ngx's remote user auth via header works even when disabling it for API

AssignerGitHub_M
Reserved2024-05-10
Published2024-05-15
Updated2024-06-04

Description

Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is explicitly disabled. Version 2.8.6 contains a patchc for the issue.



MEDIUM: 5.5CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

Problem types

CWE-287: Improper Authentication

Product status

>= 2.5.0, < 2.8.6
affected

References

https://github.com/paperless-ngx/paperless-ngx/security/advisories/GHSA-72w4-hxqq-c256

https://github.com/paperless-ngx/paperless-ngx/pull/6739

https://github.com/paperless-ngx/paperless-ngx/commit/ed05b40ba461641b1b59b0a92f51f3f6a66ce180

https://github.com/paperless-ngx/paperless-ngx/releases/tag/v2.8.6

cve.org CVE-2024-35184

nvd.nist.gov CVE-2024-35184

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-35184
© Copyright 2024 THREATINT. Made in Cyprus with +