Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. kinto-attachment
  4. ›
  5. CVE-2024-1314

CVE-2024-1314: Kinto Attachment's attachments can be replaced on read-only records

February 8, 2024

Impact

The attachment file of an existing record can be replaced if the user has "read" permission on one of the parent (collection or bucket).

And if the "read" permission is given to "system.Everyone" on one of the parent, then the attachment can be replaced on a record using an anonymous request.

Note that if the parent has no explicit read permission, then the records attachments are safe.

Patches

  • Patch released in kinto-attachment 6.4.0
  • https://github.com/Kinto/kinto-attachment/commit/f4a31484f5925cbc02b59ebd37554538ab826ca1

Workarounds

None if the read permission has to remain granted.

Updating to 6.4.0 or applying the patch individually (if updating is not feasible) is strongly recommended.

References

  • https://bugzilla.mozilla.org/show_bug.cgi?id=1879034

References

  • bugzilla.mozilla.org/show_bug.cgi?id=1879034
  • github.com/Kinto/kinto-attachment/commit/f4a31484f5925cbc02b59ebd37554538ab826ca1
  • github.com/Kinto/kinto-attachment/security/advisories/GHSA-hvp4-vrv2-8wrq
  • github.com/advisories/GHSA-hvp4-vrv2-8wrq

Code Behaviors & Features

Detect and mitigate CVE-2024-1314 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 6.3.2

Fixed versions

  • 6.4.0

Solution

Upgrade to version 6.4.0 or above.

Source file

pypi/kinto-attachment/CVE-2024-1314.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:22 +0000.