Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Untriaged
created 3 months, 3 weeks ago
Insecure direct object reference

Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.

Affected products

pretix
  • <2025.10.0
  • <2025.8.0
  • <2025.9.0
  • <2025.11.0

Matching in nixpkgs

pkgs.pretix-banktool

Automatic bank data upload tool for pretix (with FinTS client)

Package maintainers