CVE-2016-1587

Source
https://cve.org/CVERecord?id=CVE-2016-1587
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-1587.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-1587
Published
2019-04-22T16:29:01.413Z
Modified
2026-04-10T03:48:16.024312Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could have used the controls to remotely add a valid, but malicious, snap package, from the Store, potentially using system resources without permission from the legitimate administrator of the system.

References

Affected packages

Git / github.com/canonical/snapweb

Affected ranges

Type
GIT
Repo
https://github.com/canonical/snapweb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/snapcore/snapweb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.21.2"
        }
    ]
}

Affected versions

0.*
0.20

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-1587.json"