PT-2021-23960 · Patrowl · Patrowl
Ktg9
+1
·
Published
2021-12-14
·
Updated
2022-08-09
·
CVE-2021-43828
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
PatrOwl versions prior to 1.77
Description:
The issue is related to improper privilege management in PatrowlManager, allowing unlogged-in users to download all finding import files. The files are stored under
/media/imports/<owner id>/<tmp file>, where owner id is predictable and tmp file follows a predictable format, such as import <owner id> <time created>. This predictability enables unauthorized access to the files.Recommendations:
Update to version 1.7.7 as soon as possible.
As a temporary workaround, consider restricting access to the
/media/imports/ directory until the update is applied.
Avoid using predictable filenames for import files until the issue is resolved.
There are no known workarounds other than updating to the fixed version.Exploit
Fix
Improper Privilege Management
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Patrowl