In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
High CVSS 7.4
Summary
In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/muety/wakapi/commit/ce91eac2c2d9b29a00873554d2ecef76f10b9087
- https://github.com/muety/wakapi/releases/tag/2.17.6
- https://github.com/muety/wakapi/security/advisories/GHSA-x48w-3rq3-w2pq
Timeline
- nvd_ingest NVD