High severity7.5NVD Advisory· Published Mar 6, 2023· Updated Jun 17, 2026
CVE-2023-27891
CVE-2023-27891
Description
rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pretixPyPI | >= 4.17.0, < 4.17.1 | 4.17.1 |
pretixPyPI | >= 4.16.0, < 4.16.1 | 4.16.1 |
pretixPyPI | < 4.15.1 | 4.15.1 |
Affected products
5- rami.io/pretixdescription
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-r76w-3wwq-jv6vghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-27891ghsaADVISORY
- pretix.eu/about/en/blog/20230306-release-4171/nvdVendor Advisory
- github.com/pypa/advisory-database/tree/main/vulns/pretix/PYSEC-2023-42.yamlghsaWEB
- pretix.eu/about/en/blog/20230306-release-4171ghsaWEB
News mentions
0No linked articles in our index yet.