Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication. This vulnerability has been patched in v0.2.7.
Metrics
Affected Vendors & Products
References
History
Tue, 31 Dec 2024 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 30 Dec 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication. This vulnerability has been patched in v0.2.7. | |
Title | Simofa Allows Unauthenticated Access to API Routes | |
Weaknesses | CWE-306 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-12-30T18:20:00.532Z
Updated: 2024-12-30T23:14:04.231Z
Reserved: 2024-12-30T16:06:07.597Z
Link: CVE-2024-56799
Vulnrichment
Updated: 2024-12-30T23:13:59.770Z
NVD
Status : Received
Published: 2024-12-30T19:15:08.160
Modified: 2024-12-30T19:15:08.160
Link: CVE-2024-56799
Redhat
No data.