Description
Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication. This vulnerability has been patched in v0.2.7.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53432 | Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication. This vulnerability has been patched in v0.2.7. |
References
History
Tue, 31 Dec 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Dec 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, some API routes may be publicly accessible when they should require authentication. This vulnerability has been patched in v0.2.7. | |
| Title | Simofa Allows Unauthenticated Access to API Routes | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-30T23:14:04.231Z
Reserved: 2024-12-30T16:06:07.597Z
Link: CVE-2024-56799
Updated: 2024-12-30T23:13:59.770Z
Status : Deferred
Published: 2024-12-30T19:15:08.160
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-56799
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD