PT-2021-18225 · Npm · A12Nserver

CVE-2021-29452

·

Published

2021-04-16

·

Updated

2022-08-03

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: a12n-server versions 0.18.0 through 0.18.1
Description: The issue concerns a12n-server, an npm package for simple authentication. A feature to edit users via a new HAL-Form was introduced in version 0.18.0 but was incorrectly made accessible to all logged-in users due to a privilege checking error. This feature should have been restricted to admins only.
Recommendations: For a12n-server versions 0.18.0 through 0.18.1, update to version 0.18.2 to resolve the issue. As a temporary workaround, consider restricting access to the user editing feature until the update to version 0.18.2 is applied.

Fix

Incorrect Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29452
GHSA-8HW9-22V6-9JR9

Affected Products

A12Nserver