Private Shelf Information Disclosure Vulnerability Affects Calibre-Web
CVE-2021-3986

4.3MEDIUM

Key Information:

Vendor
Janeczku
Status
Janeczku/calibre-web
Vendor
CVE Published:
15 November 2024

Summary

A vulnerability identified in Janeczku's Calibre-Web allows unauthorized users to access the names of private shelves that belong to others. This issue arises due to improper error handling, specifically in the file shelf.py at line 221. When a user attempts to remove a book from a shelf they do not own, the application inadvertently discloses the name of that private shelf through an error message. This flaw not only highlights potential privacy breaches but also underscores the necessity for robust access controls within the application to safeguard user data against unauthorized access.

Affected Version(s)

janeczku/calibre-web <= unspecified

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.