VDB
Sign up
HIGH7.5

PYSEC-2022-43141

Quick fix

PYSEC-2022-43141 — motioneye: upgrade to the fixed version with the command below.

pip install --upgrade 'motioneye>=0.43.1b1'

Details

MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/motioneye
Introduced in: 0Fixed in: 0.43.1b1
Fixpip install --upgrade 'motioneye>=0.43.1b1'

References