hunvreus/devpush

hunvreus/devpush

Releases36
Frequency4 days 17 hours
Last Release
Stars4.72K
Like Vercel, but open source and for all languages.

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
2.6 LOW1.4 LOW

A vulnerability was detected in hunvreus devpush up to 0.4.6. Affected by this issue is the function reset_storage of the file app/workers/tasks/storage.py of the component Storage Reset Failure Handler. The manipulation results in improper check or handling of exceptional conditions. A high complexity level is associated with this attack. The exploitation is known to be difficult. The project was informed of the problem early through an issue report but has not responded yet.

4.3 MEDIUM

An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to malicious sites via supplying a crafted URL.