Логотип exploitDog
bind:CVE-2021-45389
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-45389

Количество 2

Количество 2

nvd логотип

CVE-2021-45389

около 4 лет назад

A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This affects StarWind SAN and NAS build 1578 and StarWind Command Center build 6864.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34rp-625w-j33p

около 4 лет назад

StarWind SAN & NAS build 1578 and StarWind Command Center Build 6864 Update Manager allows authentication with JTW token which is signed with any key. An attacker could use self-signed JTW token to bypass authentication resulting in escalation of privileges.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-45389

A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This affects StarWind SAN and NAS build 1578 and StarWind Command Center build 6864.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-34rp-625w-j33p

StarWind SAN & NAS build 1578 and StarWind Command Center Build 6864 Update Manager allows authentication with JTW token which is signed with any key. An attacker could use self-signed JTW token to bypass authentication resulting in escalation of privileges.

CVSS3: 9.8
1%
Низкий
около 4 лет назад

Уязвимостей на страницу