CVE Vulnerabilities

CVE-2021-23264

Transmission of Private Resources into a New Sphere ('Resource Leak')

Published: Dec 02, 2021 | Modified: Nov 21, 2024
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.

Weakness

The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.

Affected Software

NameVendorStart VersionEnd Version
Crafter_cmsCraftercms3.1.0 (including)3.1.15 (excluding)

References