PT-2021-18225 · Npm · A12Nserver
Published
2021-04-16
·
Updated
2022-08-03
·
CVE-2021-29452
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
a12n-server versions 0.18.0 through 0.18.1
Description:
The issue concerns a12n-server, an npm package for simple authentication. A feature to edit users via a new HAL-Form was introduced in version 0.18.0 but was incorrectly made accessible to all logged-in users due to a privilege checking error. This feature should have been restricted to admins only.
Recommendations:
For a12n-server versions 0.18.0 through 0.18.1, update to version 0.18.2 to resolve the issue.
As a temporary workaround, consider restricting access to the user editing feature until the update to version 0.18.2 is applied.
Fix
Incorrect Authorization
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
A12Nserver