PT-2021-21341 · 1Password · 1Password Connect Server

Published

2021-07-15

·

Updated

2021-08-05

·

CVE-2021-36758

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions 1Password Connect server version 1.2 and earlier
Description The issue is related to missing validation checks in the 1Password Connect server, allowing users to create Secrets Automation access tokens for privilege escalation. Malicious users authorized to create these tokens can access beyond their authorized limits, but only within the existing authorizations of the Secret Automation the token is created in.
Recommendations For versions prior to 1.2, update to version 1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Secrets Automation access token creation feature to minimize the risk of exploitation.

Fix

Incorrect Authorization

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36758

Affected Products

1Password Connect Server