CVE Vulnerabilities

CVE-2021-3818

Reliance on Cookies without Validation and Integrity Checking

Published: Sep 27, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking

Weakness

The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.

Affected Software

NameVendorStart VersionEnd Version
GravGetgrav*1.7.22 (excluding)

Potential Mitigations

References