GHSA-hh7j-pg39-q563, CVE-2023-33175
pypi/toui
toui allows user-specific variables to be shared between users
Websites that use Website.user_vars
property in versions.
It affects versions v2.0.1 to v2.4.0. Please upgrade to v2.4.1
Do not use Website.user_vars
in websites when using versions v2.0.1 to v2.4.0. Also, do not use Website.signin_user()
in version v2.4.0 only.
ToUI is using Flask-Caching (SimpleCache) to store user variables. My misunderstanding was that these caches are stored in the client's browser, but it seems that these are stored in the server side.
All versions starting from 2.0.1 before 2.4.1
Upgrade to version 2.4.1 or above.
2023-05-25
source |