Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, it is possible to create a URL that acts as an open redirect. The vulnerability has been patched in version 1.4.97 of the master branch.
References
Link | Resource |
---|---|
https://github.com/jhpyle/docassemble/commit/4801ac7ff7c90df00ac09523077930cdb6dea2aa | Patch |
https://github.com/jhpyle/docassemble/security/advisories/GHSA-7wxf-r2qv-9xwr | Patch Third Party Advisory |
https://github.com/jhpyle/docassemble/commit/4801ac7ff7c90df00ac09523077930cdb6dea2aa | Patch |
https://github.com/jhpyle/docassemble/security/advisories/GHSA-7wxf-r2qv-9xwr | Patch Third Party Advisory |
Configurations
History
02 Sep 2025, 13:39
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:jhpyle:docassemble:*:*:*:*:*:*:*:* | |
First Time |
Jhpyle
Jhpyle docassemble |
|
References | () https://github.com/jhpyle/docassemble/commit/4801ac7ff7c90df00ac09523077930cdb6dea2aa - Patch | |
References | () https://github.com/jhpyle/docassemble/security/advisories/GHSA-7wxf-r2qv-9xwr - Patch, Third Party Advisory |
21 Nov 2024, 09:04
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/jhpyle/docassemble/commit/4801ac7ff7c90df00ac09523077930cdb6dea2aa - | |
References | () https://github.com/jhpyle/docassemble/security/advisories/GHSA-7wxf-r2qv-9xwr - |
21 Mar 2024, 02:52
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-21 02:52
Updated : 2025-09-02 13:39
NVD link : CVE-2024-27291
Mitre link : CVE-2024-27291
CVE.ORG link : CVE-2024-27291
JSON object : View
Products Affected
jhpyle
- docassemble
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')