CVE-2023-27891
HIGH7.5EPSS 0.34%Insufficient Session Expiration in pretix
Published: 3/7/2023Modified: 10/21/2024
Description
rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.
Affected packages (2)
- PyPI/pretix>= 4.17.0, < 4.17.1
- PyPI/pretixfrom 0, < 4.17.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
References (5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2023-27891
- ADVISORYhttps://pretix.eu/about/en/blog/20230306-release-4171/
- PATCHhttps://github.com/thufschmitt/pretix-nix
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/pretix/PYSEC-2023-42.yaml
- WEBhttps://pretix.eu/about/en/blog/20230306-release-4171