Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-43781

Опубликовано: 06 дек. 2021
Источник: nvd
CVSS3: 6.4
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable in a default installation of InvenioRDM. An authenticated a user is able via REST API calls to publish draft records of other users if they know the record identifier and the draft validates (e.g. all require fields filled out). An attacker is not able to modify the data in the record, and thus e.g. cannot change a record from restricted to public. The problem is patched in Invenio-Drafts-Resources v0.13.7 and 0.14.6, which is part of InvenioRDM v6.0.1 and InvenioRDM v7.0 respectively.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:inveniosoftware:invenio-drafts-resources:*:*:*:*:*:*:*:*
Версия до 0.13.7 (исключая)
cpe:2.3:a:inveniosoftware:invenio-drafts-resources:*:*:*:*:*:*:*:*
Версия от 0.14.0 (включая) до 0.14.6 (исключая)

EPSS

Процентиль: 35%
0.00144
Низкий

6.4 Medium

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-862
CWE-863

Связанные уязвимости

CVSS3: 6.4
github
около 4 лет назад

Permissions not properly checked in Invenio-Drafts-Resources

EPSS

Процентиль: 35%
0.00144
Низкий

6.4 Medium

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-862
CWE-863