Private Shelf Information Disclosure Vulnerability Affects Calibre-Web
CVE-2021-3986
What is CVE-2021-3986?
A vulnerability identified in Janeczku's Calibre-Web allows unauthorized users to access the names of private shelves that belong to others. This issue arises due to improper error handling, specifically in the file shelf.py at line 221. When a user attempts to remove a book from a shelf they do not own, the application inadvertently discloses the name of that private shelf through an error message. This flaw not only highlights potential privacy breaches but also underscores the necessity for robust access controls within the application to safeguard user data against unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
janeczku/calibre-web <= unspecified
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
