Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-43834

Опубликовано: 16 дек. 2021
Источник: nvd
CVSS3: 9.1
CVSS3: 9.8
CVSS2: 6.5
EPSS Низкий

Описание

eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single sign-on authentication option such as LDAP or SAML. It impacts instances where LDAP or SAML is used for authentication instead of the (default) local password mechanism. Users should upgrade to at least version 4.2.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elabftw:elabftw:*:*:*:*:*:*:*:*
Версия до 4.2.0 (исключая)

EPSS

Процентиль: 55%
0.00322
Низкий

9.1 Critical

CVSS3

9.8 Critical

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-287

EPSS

Процентиль: 55%
0.00322
Низкий

9.1 Critical

CVSS3

9.8 Critical

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-287