CVE Vulnerabilities

CVE-2021-23264

Transmission of Private Resources into a New Sphere ('Resource Leak')

Published: Dec 02, 2021 | Modified: Nov 21, 2024
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.

Weakness

The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.

Affected Software

Name Vendor Start Version End Version
Crafter_cms Craftercms 3.1.0 (including) 3.1.15 (excluding)

References