Junglewise Threat Intelligence

PYSEC-2023-293 - An authentication bypass vulnerability has been found in Repox, which allows a remote user to send a specially crafted POST request, due to

Severity: low · CVSS 3.1 · Published 2023-12-13

Technologies: repox (PyPI). Vendors: PyPI.

Executive brief

An authentication bypass vulnerability has been found in Repox, which allows a remote user to send a specially crafted POST request, due to the lack of any authentication method, resulting in the alteration or creation of users.

Affected products

  • PyPI repox

Related threats