—
PYSEC-2022-43008
Quick fix
PYSEC-2022-43008 — rdiffweb: upgrade to the fixed version with the command below.
pip install --upgrade 'rdiffweb>=d1aaa96b665a39fba9e98d6054a9de511ba0a837'Details
Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/rdiffweb
Introduced in:
0Fixed in: d1aaa96b665a39fba9e98d6054a9de511ba0a837Fix
pip install --upgrade 'rdiffweb>=d1aaa96b665a39fba9e98d6054a9de511ba0a837'References
- https://github.com/ikus060/rdiffweb/commit/d1aaa96b665a39fba9e98d6054a9de511ba0a837[FIX]
- https://huntr.dev/bounties/c62126dc-d9a6-4d3e-988d-967031876c58[EVIDENCE]
- https://huntr.dev/bounties/c62126dc-d9a6-4d3e-988d-967031876c58[FIX]
- https://huntr.dev/bounties/c62126dc-d9a6-4d3e-988d-967031876c58[WEB]
- https://github.com/advisories/GHSA-wf33-6x33-wcf9[ADVISORY]