PT-2021-23207 · Openolat · Openolat

Gnaegi

·

Published

2021-12-10

·

Updated

2022-08-09

·

CVE-2021-41242

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenOlat versions prior to 15.5.12 and 16.0.5
Description A path traversal issue exists in OpenOlat, allowing an attacker to create directory structures and write files anywhere on the target system by providing a filename with a relative path as a parameter in some REST methods. This could be used to write files in the web root folder or outside, depending on system configuration and application server user permissions. The attack requires an OpenOlat user account, an enabled REST API, and rights to call vulnerable REST calls.
Recommendations For versions prior to 15.5.12, update to version 15.5.12 or later. For versions prior to 16.0.5, update to version 16.0.5 or later. As a temporary workaround, consider disabling the REST module or limiting its access via firewall or web-server rules to only trusted systems.

Fix

Relative Path Traversal

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2021-41242
GHSA-62HV-RFP4-HMRM

Affected Products

Openolat