lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3...
Moderate severity
Unreviewed
Published
Dec 15, 2023
to the GitHub Advisory Database
•
Updated Dec 28, 2023
Description
Published by the National Vulnerability Database
Dec 15, 2023
Published to the GitHub Advisory Database
Dec 15, 2023
Last updated
Dec 28, 2023
lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3 performs post-Unicode normalization, which may allow bypass of intended access restrictions, such as when U+1FEF is converted to a backtick.
References