PT-2021-18225 · Npm · A12Nserver

Published

2021-04-16

·

Updated

2022-08-03

·

CVE-2021-29452

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: a12n-server versions 0.18.0 through 0.18.1
Description: The issue concerns a12n-server, an npm package for simple authentication. A feature to edit users via a new HAL-Form was introduced in version 0.18.0 but was incorrectly made accessible to all logged-in users due to a privilege checking error. This feature should have been restricted to admins only.
Recommendations: For a12n-server versions 0.18.0 through 0.18.1, update to version 0.18.2 to resolve the issue. As a temporary workaround, consider restricting access to the user editing feature until the update to version 0.18.2 is applied.

Fix

Incorrect Authorization

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2021-29452
GHSA-8HW9-22V6-9JR9

Affected Products

A12Nserver