Skip to content

Improper Authorization in eLabFTW

Low
NicolasCARPi published GHSA-63qq-hw97-8q7x Jul 25, 2022

Package

docker elabftw (docker)

Affected versions

<4.3.4

Patched versions

4.3.4

Description

Impact

A vulnerability was discovered and reported ethically by @xskullboyx. It allows a logged in user to read a template without being authorized to do so.

Patches

This vulnerability has been patched in 4.3.4.

Workarounds

No workaround, just upgrade.

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2022-31178

Weaknesses