Executive brief
Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacharacters in the user name, as demonstrated by ".*".
Affected products
- PyPI radicale
Junglewise Threat Intelligence
CVE-2015-8748 · Severity: low · CVSS 3 · Published 2016-02-03
Technologies: radicale (PyPI). Vendors: PyPI.
Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacharacters in the user name, as demonstrated by ".*".