NIXPKGS-2026-0008
published on
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse ignored package pretix-banktool
- @LeSuisse deleted maintainer @mweinelt maintainer.delete
- @LeSuisse accepted
- @LeSuisse published on GitHub
Insecure direct object reference
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.
References
-
https://pretix.eu/about/en/blog/20251218-release-2025-10-1/ vendor-advisory
Affected products
pretix
- <2025.8.0
- <2025.10.0
- <2025.9.0
- <2025.11.0
Matching in nixpkgs
Ignored packages (1)
pkgs.pretix-banktool
Automatic bank data upload tool for pretix (with FinTS client)
Package maintainers
Ignored maintainers (1)
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>