Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3244 | An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not verifying if the user has the necessary permissions to create a public shelf. This issue can lead to unauthorized actions being performed by users. |
Github GHSA |
GHSA-fj5v-w2jp-wqvj | Improper Access Control in janeczku/calibre-web |
Tue, 19 Nov 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Janeczku
Janeczku calibre-web |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:janeczku:calibre-web:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Janeczku
Janeczku calibre-web |
|
| Metrics |
cvssV3_1
|
Fri, 15 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Calibre-web Project
Calibre-web Project calibre-web |
|
| CPEs | cpe:2.3:a:calibre-web_project:calibre-web:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Calibre-web Project
Calibre-web Project calibre-web |
|
| Metrics |
ssvc
|
Fri, 15 Nov 2024 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not verifying if the user has the necessary permissions to create a public shelf. This issue can lead to unauthorized actions being performed by users. | |
| Title | Improper Access Control in janeczku/calibre-web | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-11-15T18:28:12.925Z
Reserved: 2021-11-20T12:01:47.041Z
Link: CVE-2021-3987
Updated: 2024-11-15T18:28:08.988Z
Status : Analyzed
Published: 2024-11-15T11:15:06.610
Modified: 2024-11-19T15:44:38.113
Link: CVE-2021-3987
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA