Skip to content

Names of Restricted Books Visible Through Shelves List View

Low
ssddanbrown published GHSA-c32x-84w6-5mxq May 12, 2020

Package

No package listed

Affected versions

>= v0.28.0 && < v0.29.3

Patched versions

v0.29.3

Description

Impact

The name of a restricted book could be viewed by non-authorised users when the book was on a shelf, and the shelves were viewed in "List View". This could expose book names to those that did not have permission to see them, when part of a shelf.

Patches

This has been patched in version v0.29.3.

Workarounds

Please update otherwise you could temporarily change the name of any private books to remove any sensitive content.

References

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs