NIXPKGS-2026-0008
published on 11 Jan 2026
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse removed package pretix-banktool
- @LeSuisse removed maintainer @mweinelt
- @LeSuisse accepted
- @LeSuisse published on GitHub
Insecure direct object reference
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.
Affected products
pretix
- <2025.9.0
- <2025.8.0
- <2025.10.0
- <2025.11.0
Package maintainers
Ignored maintainers (1)
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>