Private Shelf Information Disclosure Vulnerability Affects Calibre-Web
CVE-2021-3986
4.3MEDIUM
Key Information:
- Vendor
- Janeczku
- Status
- Janeczku/calibre-web
- Vendor
- CVE Published:
- 15 November 2024
Summary
A vulnerability identified in Janeczku's Calibre-Web allows unauthorized users to access the names of private shelves that belong to others. This issue arises due to improper error handling, specifically in the file shelf.py at line 221. When a user attempts to remove a book from a shelf they do not own, the application inadvertently discloses the name of that private shelf through an error message. This flaw not only highlights potential privacy breaches but also underscores the necessity for robust access controls within the application to safeguard user data against unauthorized access.
Affected Version(s)
janeczku/calibre-web <= unspecified
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved