PT-2021-23956 · Seafile · Seafile
Published
2021-12-14
·
Updated
2021-12-21
·
CVE-2021-43820
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Seafile (affected versions not specified)
Description:
The issue affects Seafile, an open source cloud storage system, where a sync token is used to authorize access to library data. The token is cached in memory to improve performance, but the server fails to check if the token is associated with the specific library in the URL when it exists in the cache. This allows an attacker to use any valid sync token to access data from any known library, provided they can first determine the library's ID, which is a random UUID.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seafile