CVE-2016-1587

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
22/04/2019
Last modified:
09/10/2019

Description

The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could have used the controls to remotely add a valid, but malicious, snap package, from the Store, potentially using system resources without permission from the legitimate administrator of the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:snapweb:snapweb:*:*:*:*:*:*:*:* 0.21.2 (excluding)