VDB
Sign up
—

PYSEC-2016-37

Quick fix

PYSEC-2016-37 — radicale: upgrade to the fixed version with the command below.

pip install --upgrade 'radicale>=4bfe7c9f7991d534c8b9fbe153af9d341f925f98'

Details

Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacharacters in the user name, as demonstrated by ".*".

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/radicale
Introduced in: 0Fixed in: 4bfe7c9f7991d534c8b9fbe153af9d341f925f98
Fixpip install --upgrade 'radicale>=4bfe7c9f7991d534c8b9fbe153af9d341f925f98'

References