« Volver al listado

CVE-2020-35175

Estado: ModificadaMedia (5.3)—

Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-35175",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-12-11T23:15:14.607",
  "references": [
    {
      "url": "https://github.com/frappe/frappe/pull/11228",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/frappe/frappe/pull/11237",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/frappe/frappe/pull/11228",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/frappe/frappe/pull/11237",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API."
    },
    {
      "lang": "es",
      "value": "Frappe Framework versiones 12 y 13, no comprueban apropiadamente el método HTTP para la API frappe.client"
    }
  ],
  "lastModified": "2026-06-17T03:13:28.580",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:frappe:frappe:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0116070D-4E37-4A98-95B0-565197AB8795",
              "versionEndIncluding": "12.12.0",
              "versionStartIncluding": "12.0.0"
            },
            {
              "criteria": "cpe:2.3:a:frappe:frappe:13.0.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0FA29C86-7D51-41DE-9E18-9932F9A0DBD5"
            },
            {
              "criteria": "cpe:2.3:a:frappe:frappe:13.0.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "070C124B-3E43-4EE3-B12D-EDC25DF3AD2D"
            },
            {
              "criteria": "cpe:2.3:a:frappe:frappe:13.0.0:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48FAB577-61D8-4FAF-9FBB-05DF454454AD"
            },
            {
              "criteria": "cpe:2.3:a:frappe:frappe:13.0.0:beta4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F0391DA-3197-41DC-8C3B-C65D90D4DD15"
            },
            {
              "criteria": "cpe:2.3:a:frappe:frappe:13.0.0:beta5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF545F24-F328-4C92-B3D3-81DF8F610B41"
            },
            {
              "criteria": "cpe:2.3:a:frappe:frappe:13.0.0:beta6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6EBC337A-BC86-4DB7-96B8-EE89419535EE"
            },
            {
              "criteria": "cpe:2.3:a:frappe:frappe:13.0.0:beta7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8DDFA99-5427-49BC-AA27-29AA4DD84960"
            },
            {
              "criteria": "cpe:2.3:a:frappe:frappe:13.0.0:beta8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FFF74A2-97F1-43B3-A30C-FBDA77B60D83"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}