First published: Wed Mar 18 2020(Updated: )
In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Frappe LMS | =11.0.0 | |
Frappe LMS | =12.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Frappe issue is CVE-2019-20529.
The title of this vulnerability is 'In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12 data files generated with Prepared Report were being stored as public files instead of private files'.
The severity of CVE-2019-20529 is high with a CVSS score of 7.5.
Frappe versions 11.0.0 and 12.0.0 are affected by this vulnerability.
To fix this vulnerability, apply the patches provided in the following GitHub pull requests: [Link1](https://github.com/frappe/frappe/pull/8884) and [Link2](https://github.com/frappe/frappe/pull/8885).