PT-2022-11621 · Caldera · Caldera
Published
2022-01-12
·
Updated
2022-07-12
·
CVE-2021-42562
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
CALDERA version 2.8.1
Description
The issue is related to improper segregation of user privileges. Non-admin users have access to read and modify configuration or other components that should only be accessible by admin users.
Recommendations
For CALDERA version 2.8.1, consider restricting access to configuration components to minimize the risk of exploitation by non-admin users. As a temporary workaround, review and adjust user privileges to ensure that only admin users have access to sensitive components until a proper fix is available.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Caldera