Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacharacters in the user name, as demonstrated by ".*".
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade radicale | Mar 14, 2016 | Jan 30, 2016 |
| Freebsd | — | Upgrade py34-radicaleUpgrade py27-radicaleUpgrade py32-radicaleUpgrade py33-radicale | Dec 10, 2025 | Jan 29, 2016 |
| Ubuntu | — | Upgrade radicale | Nov 19, 2024 | Feb 3, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub