CVE-2024-35184: paperless-ngx's remote user auth via header works even when disabling it for API
Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is explicitly disabled. Version 2.8.6 contains a patchc for the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35184?
CVE-2024-35184 has been classified with a severity level that indicates a critical risk due to unauthorized API access.
How do I fix CVE-2024-35184?
To remediate CVE-2024-35184, upgrade to Paperless-ngx version 2.8.6 or later.
What versions are affected by CVE-2024-35184?
CVE-2024-35184 affects Paperless-ngx versions from 2.5.0 to 2.8.5.
What type of vulnerability is CVE-2024-35184?
CVE-2024-35184 is a remote user authentication issue that allows unintended access to API endpoints.
What are the potential impacts of CVE-2024-35184?
The potential impacts of CVE-2024-35184 include unauthorized access to sensitive documents and data exposure.