PT-2021-23106 · Unknown · Survey Solutions
Vavalomi
·
Published
2021-10-04
·
Updated
2022-08-12
·
CVE-2021-41123
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Survey Solutions versions prior to 21.09.1
Description
The issue concerns the Headquarters application of Survey Solutions, a survey management and data collection system. In affected versions, the
/metrics endpoint is published and available to any user. This endpoint exposes aggregate counters, including the count of interviews or assignments, but does not expose survey answers.Recommendations
For versions prior to 21.09.1, consider disabling the
/metrics endpoint to prevent unauthorized access to aggregate counters until a version with the endpoint turned off by default can be implemented.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Survey Solutions