Skip to content

No limit set on "notes" fields

Moderate
SchrodingersGat published GHSA-mmm6-rwf8-ghv3 Jun 20, 2022

Package

No package listed

Affected versions

< 0.8.0

Patched versions

0.8.0

Description

Impact

Affected version of InvenTree do not provide an upper length on the "notes" field on various models, allowing users to upload arbitrarily large character data to these fields.

Patches

  • This issue has been addressed in the upcoming 0.8.0 stable release.
  • Refer to #3231

Workarounds

None

References

https://huntr.dev/bounties/57b0f272-a97f-4cb3-b546-c863c68a561a/

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

No known CVE

Weaknesses

Credits