CVE Vulnerabilities

CVE-2021-36802

Uncaught Exception

Published: Aug 04, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Akaunting version 2.1.12 and earlier suffers from a denial-of-service issue that is triggered by setting a malformed locale variable and sending it in an otherwise normal HTTP POST request. This issue was fixed in version 2.1.13 of the product.

Weakness

An exception is thrown from a function, but it is not caught.

Affected Software

Name Vendor Start Version End Version
Akaunting Akaunting * 2.1.12 (including)

References