SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-29452

A new HAL-Form was added to allow editing users in version 0.18.0.

MEDIUM 6.5EPSS 0.78%

Does this matter?

Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.

Description

a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow editing users in version 0.18.0. This feature should only have been accessible to admins. Unfortunately, privileges were incorrectly checked allowing any logged in user to make this change. Patched in v0.18.2.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.78% probability · 54th percentile
CISA KEV
Not listed
Weakness
CWE-269, CWE-863
Affected
curveballjs/a12n-server
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.