PT-2022-11621 · Caldera · Caldera

Published

2022-01-12

·

Updated

2022-07-12

·

CVE-2021-42562

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions CALDERA version 2.8.1
Description The issue is related to improper segregation of user privileges. Non-admin users have access to read and modify configuration or other components that should only be accessible by admin users.
Recommendations For CALDERA version 2.8.1, consider restricting access to configuration components to minimize the risk of exploitation by non-admin users. As a temporary workaround, review and adjust user privileges to ensure that only admin users have access to sensitive components until a proper fix is available.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42562

Affected Products

Caldera