Show plain JSON{"id": "CVE-2024-35184", "metrics": {"cvssMetricV31": [{"type": "Secondary", "source": "security-advisories@github.com", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 5.5, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L", "integrityImpact": "LOW", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "LOW", "privilegesRequired": "LOW", "confidentialityImpact": "LOW"}, "impactScore": 3.4, "exploitabilityScore": 2.1}]}, "published": "2024-05-15T22:15:08.867", "references": [{"url": "https://github.com/paperless-ngx/paperless-ngx/commit/ed05b40ba461641b1b59b0a92f51f3f6a66ce180", "source": "security-advisories@github.com"}, {"url": "https://github.com/paperless-ngx/paperless-ngx/pull/6739", "source": "security-advisories@github.com"}, {"url": "https://github.com/paperless-ngx/paperless-ngx/releases/tag/v2.8.6", "source": "security-advisories@github.com"}, {"url": "https://github.com/paperless-ngx/paperless-ngx/security/advisories/GHSA-72w4-hxqq-c256", "source": "security-advisories@github.com"}, {"url": "https://github.com/paperless-ngx/paperless-ngx/commit/ed05b40ba461641b1b59b0a92f51f3f6a66ce180", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://github.com/paperless-ngx/paperless-ngx/pull/6739", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://github.com/paperless-ngx/paperless-ngx/releases/tag/v2.8.6", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://github.com/paperless-ngx/paperless-ngx/security/advisories/GHSA-72w4-hxqq-c256", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Awaiting Analysis", "weaknesses": [{"type": "Secondary", "source": "security-advisories@github.com", "description": [{"lang": "en", "value": "CWE-287"}]}], "descriptions": [{"lang": "en", "value": "Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is explicitly disabled. Version 2.8.6 contains a patchc for the issue."}, {"lang": "es", "value": "Paperless-ngx es un sistema de gesti\u00f3n de documentos que transforma documentos f\u00edsicos en un archivo en l\u00ednea con capacidad de b\u00fasqueda. A partir de la versi\u00f3n 2.5.0 y antes de la versi\u00f3n 2.8.6, la autenticaci\u00f3n de usuario remoto permite el acceso a la API incluso si el acceso a la API est\u00e1 expl\u00edcitamente deshabilitado. La versi\u00f3n 2.8.6 contiene un parche para el problema."}], "lastModified": "2024-11-21T09:19:53.333", "sourceIdentifier": "security-advisories@github.com"}