CVE-2024-39313

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-39313
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39313.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-39313
Aliases
  • GHSA-rf2q-5q4q-5fwr
Published
2024-07-01T21:23:38.247Z
Modified
2025-12-05T05:18:50.559378Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
toy-blog Improper Input Validation vulnerability
Details

toy-blog is a headless content management system implementation. Starting in version 0.5.4 and prior to version 0.6.1, articles with private visibility can be read if the reader does not set credentials for the request. Users should upgrade to 0.6.1 or later to receive a patch. No known workarounds are available.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/39xxx/CVE-2024-39313.json"
}
References

Affected packages

Git / github.com/kisaragieffective/toy-blog

Affected ranges

Type
GIT
Repo
https://github.com/kisaragieffective/toy-blog
Events

Affected versions

0.*

0.5.4
0.6.0