id: PYSEC-2022-43001 details: Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6. aliases: - CVE-2022-4018 - GHSA-4wph-9vrm-6v3w modified: '2023-05-04T04:29:28.960174Z' published: '2022-11-16T13:15:00Z' references: - type: FIX url: https://github.com/ikus060/rdiffweb/commit/f2a32f2a9f3fb8be1a9432ac3d81d3aacdb13095 - type: EVIDENCE url: https://huntr.dev/bounties/5340c2f6-0252-40f6-8929-cca5d64958a5 - type: WEB url: https://huntr.dev/bounties/5340c2f6-0252-40f6-8929-cca5d64958a5 - type: ADVISORY url: https://github.com/advisories/GHSA-4wph-9vrm-6v3w affected: - package: name: rdiffweb ecosystem: PyPI purl: pkg:pypi/rdiffweb ranges: - type: GIT repo: https://github.com/ikus060/rdiffweb events: - introduced: '0' - fixed: f2a32f2a9f3fb8be1a9432ac3d81d3aacdb13095 - type: ECOSYSTEM events: - introduced: '0' - fixed: 2.4.11a1 versions: - 0.10.0 - 0.10.2 - 0.10.3 - 0.10.4 - 0.10.5 - 0.10.6 - 0.10.7 - 0.10.8 - 0.10.9 - 0.9.2.dev1 - 0.9.3 - 0.9.4 - 0.9.5 - 1.0.0 - 1.0.0a1 - 1.0.0a2 - 1.0.0a3 - 1.0.0a4 - 1.0.1 - 1.0.2 - 1.0.3 - 1.1.0 - 1.2.0 - 1.2.1 - 1.2.2 - 1.3.0 - 1.3.1 - 1.3.1b1 - 1.3.1b2 - 1.3.2 - 1.4.0 - 1.4.0b1 - 1.4.0b2 - 1.4.0b3 - 1.4.0b4 - 1.4.0b5 - 1.4.1b1 - 1.4.1b2 - 1.4.1b3 - 1.5.0 - 1.5.1b1 - 1.5.1b2 - 1.6.0b1 - 2.0.1b2 - 2.0.1b3 - 2.0.2 - 2.0.3a1 - 2.0.3a2 - 2.0.3a3 - 2.0.3a4 - 2.0.3a5 - 2.0.3a6 - 2.0.3a7 - 2.1.0 - 2.2.0 - 2.2.0.dev1 - 2.2.0a1 - 2.2.0a2 - 2.2.0a3 - 2.2.0a4 - 2.2.0a5 - 2.2.0a6 - 2.2.1 - 2.3.0 - 2.3.1 - 2.3.2 - 2.3.3 - 2.3.4 - 2.3.5 - 2.3.6 - 2.3.7 - 2.3.8 - 2.3.9 - 2.4.0 - 2.4.1 - 2.4.10 - 2.4.2 - 2.4.3 - 2.4.4 - 2.4.5 - 2.4.6 - 2.4.7 - 2.4.8 - 2.4.9