CVE-2024-27105: Frappe File Permissions can by bypassed using certain endpoints
Published Mar 20, 2024
·Updated
Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed using certain endpoints, granting less privileged users permission to delete or clone a file. Versions 14.66.3 and 15.16.0 contain a patch for this issue. No known workarounds are available.
Affected Software
3 affected components
Frappe frappe<14.66.3, <15.16.0
Frappe frappe<14.66.3
Frappe frappe>=15.0.0<15.16.0
Event History
Mar 20, 2024
CVE Published
via MITRE·06:11 PM
Data Sourced
via MITRE·06:11 PM
DescriptionSeverityWeakness
Mar 21, 2024
Data Sourced
via NVD·02:52 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27105?
CVE-2024-27105 is considered a medium severity vulnerability due to its impact on file permissions.
2
How do I fix CVE-2024-27105?
To fix CVE-2024-27105, upgrade Frappe to version 14.66.3 or 15.16.0 or later.
3
Who is affected by CVE-2024-27105?
CVE-2024-27105 affects all users of Frappe versions prior to 14.66.3 and 15.16.0.
4
What type of vulnerability is CVE-2024-27105?
CVE-2024-27105 is a file permission bypass vulnerability.
5
Can less privileged users exploit CVE-2024-27105?
Yes, less privileged users can exploit CVE-2024-27105 to gain unauthorized permissions to delete or clone files.