by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse ignored package pretix-banktool
- @LeSuisse deleted maintainer @mweinelt maintainer.delete
- @LeSuisse accepted
- @LeSuisse published on GitHub
Insecure direct object reference
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.
References
-
https://pretix.eu/about/en/blog/20251218-release-2025-10-1/ vendor-advisory
Affected products
- <2025.8.0
- <2025.11.0
- <2025.10.0
- <2025.9.0
Matching in nixpkgs
Ignored packages (1)
pkgs.pretix-banktool
Automatic bank data upload tool for pretix (with FinTS client)
Package maintainers
Ignored maintainers (1)
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>