PT-2021-24205 · Knime · Knime Server

Dawid Czarnecki

·

Published

2021-12-16

·

Updated

2023-09-28

·

CVE-2021-45097

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: KNIME Server versions 4.12.5 and earlier KNIME Server versions 4.13.x before 4.13.4
Description: The issue allows local users to read the administrator's password from a file due to inadequate file access controls when the software is installed in unattended mode.
Recommendations: For KNIME Server versions 4.12.5 and earlier, update to version 4.12.6 or later. For KNIME Server versions 4.13.x before 4.13.4, update to version 4.13.4 or later.

Exploit

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2021-45097

Affected Products

Knime Server