PT-2022-19822 · Unknown · Aleksis-Core

·

CVE-2022-29773

·

Published

2022-06-03

·

Updated

2026-07-06

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AlekSIS-Core versions 2.8.1 and below
Description An access control issue in aleksis/core/util/auth helpers.py, specifically in the ClientProtectedResourceMixin, allows attackers to access arbitrary scopes if no allowed scopes are specifically set.
Recommendations For AlekSIS-Core versions 2.8.1 and below, consider setting allowed scopes specifically to prevent attackers from accessing arbitrary scopes until a patch is available. As a temporary workaround, review and restrict access to sensitive resources to minimize the risk of exploitation.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29773
GHSA-76X2-H8H3-CWJG
PYSEC-2026-767

Affected Products

Aleksis-Core