PT-2021-23106 · Unknown · Survey Solutions

Vavalomi

·

Published

2021-10-04

·

Updated

2022-08-12

·

CVE-2021-41123

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Survey Solutions versions prior to 21.09.1
Description The issue concerns the Headquarters application of Survey Solutions, a survey management and data collection system. In affected versions, the /metrics endpoint is published and available to any user. This endpoint exposes aggregate counters, including the count of interviews or assignments, but does not expose survey answers.
Recommendations For versions prior to 21.09.1, consider disabling the /metrics endpoint to prevent unauthorized access to aggregate counters until a version with the endpoint turned off by default can be implemented.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2021-41123
GHSA-6C7J-7JF3-9P3J

Affected Products

Survey Solutions