Impact
A missing authentication flaw has been identified in the Project Upload Endpoint of the Gerapy project. The flaw, located in an unspecified function of gerapy/server/core/views.py, allows an attacker to access the upload functionality without providing any credentials. Because the endpoint accepts arbitrary uploads, an attacker could potentially upload malicious components or scripts, which may later be executed by the system or other users, thereby compromising the integrity and confidentiality of the application or the data it handles. The vulnerability is listed with a CVSS score of 6.9, indicating a medium severity level for the potential unauthorized access and the subsequent risks associated with the uploaded content.
Affected Systems
The vulnerability affects all installations of Gerapy up to and including version 0.9.13. Users running older releases or following the specific patch identified by the commit hash bd4891c60315f17611a3b7a651ffe0fba7cfe71e have been noted as susceptible.
Risk and Exploitability
The exploit is remote and has been publicly disclosed, yet the EPSS score is below 1%, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog, and no special access or elevated privileges are required to trigger the flaw. An attacker only needs the ability to send a request to the upload endpoint; authentication is not enforced, enabling unauthenticated usage and potential malicious payload delivery.
OpenCVE Enrichment