PT-2021-23956 · Seafile · Seafile

Published

2021-12-14

·

Updated

2021-12-21

·

CVE-2021-43820

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Seafile (affected versions not specified)
Description: The issue affects Seafile, an open source cloud storage system, where a sync token is used to authorize access to library data. The token is cached in memory to improve performance, but the server fails to check if the token is associated with the specific library in the URL when it exists in the cache. This allows an attacker to use any valid sync token to access data from any known library, provided they can first determine the library's ID, which is a random UUID.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43820
GHSA-M3WC-JV6R-HVV8

Affected Products

Seafile