PT-2020-13173 · Calibre · Calibre-Web

·

CVE-2020-12627

·

Published

2020-05-04

·

Updated

2024-11-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Calibre-Web version 0.6.6
Description The issue allows authentication bypass due to a hardcoded secret key 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT'.
Recommendations For Calibre-Web version 0.6.6, update the secret key to a unique and secure value to prevent authentication bypass. As a temporary workaround, consider restricting access to the application until the issue is resolved.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12627

Affected Products

Calibre-Web