Skip to content

Commit 9f6c294

Browse files
committed
GHSA/SYNC: 1 brand new advisory - 4/14/26
1 parent b1e3c15 commit 9f6c294

File tree

1 file changed

+32
-0
lines changed

1 file changed

+32
-0
lines changed
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
---
2+
gem: fat_free_crm
3+
ghsa: 9pm8-vwc5-w2hm
4+
url: https://github.com/fatfreecrm/fat_free_crm/security/advisories/GHSA-9pm8-vwc5-w2hm
5+
title:
6+
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated
7+
user can hit this endpoint and delete emails by ID
8+
date: 2026-04-14
9+
description: |
10+
Fat Free CRM has BOLA (Broken Object Level Authorization) in
11+
DELETE /emails/:id - Any authenticated user can hit this
12+
endpoint and delete emails by ID
13+
14+
### Impact
15+
16+
Authenticated users can delete emails imported into the system
17+
assigned to another user; where the
18+
[Email Dropbox](https://github.com/fatfreecrm/fat_free_crm/wiki/Email-Dropbox)
19+
is in use.
20+
21+
### Workarounds
22+
23+
Disable use of email dropbox.
24+
cvss_v3: 2.1
25+
patched_versions:
26+
- ">= 0.26.0"
27+
related:
28+
url:
29+
- https://rubygems.org/gems/fat_free_crm/versions/0.26.0
30+
- https://github.com/fatfreecrm/fat_free_crm/releases/tag/v0.26.0
31+
- https://github.com/fatfreecrm/fat_free_crm/security/advisories/GHSA-9pm8-vwc5-w2hm
32+
- https://github.com/advisories/GHSA-9pm8-vwc5-w2hm

0 commit comments

Comments
 (0)