SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-27292

The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation.

HIGH 7.5EPSS 69.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 69.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
69.49% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-706
Affected
jhpyle/docassemble
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.