PT-2021-21263 · Unknown · Xen Orchestra

R3Naissance

·

Published

2021-07-12

·

Updated

2022-07-12

·

CVE-2021-36383

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xen Orchestra versions through 5.80.0 (xo-web) and through 5.84.0 (xo-server)
Description The issue concerns mishandled authorization. An attacker can modify WebSocket resourceSet.getAll data, changing the permission field from none to admin, thereby gaining access to sensitive data sets including VMs, Backups, Audit, Users, and Groups.
Recommendations For versions through 5.80.0 (xo-web) and through 5.84.0 (xo-server), as a temporary workaround, consider restricting access to the resourceSet.getAll WebSocket endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36383
GHSA-GRVM-GCQF-GH8Q

Affected Products

Xen Orchestra