VulnerabilityModified
CVE-2021-29452
A new HAL-Form was added to allow editing users in version 0.18.0.
MEDIUM 6.5EPSS 0.78%
Does this matter?
Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.
Description
a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow editing users in version 0.18.0. This feature should only have been accessible to admins. Unfortunately, privileges were incorrectly checked allowing any logged in user to make this change. Patched in v0.18.2.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269, CWE-863
- Affected
- curveballjs/a12n-server
- Source
- security-advisories@github.com
References
- https://github.com/curveball/a12n-server/security/advisories/GHSA-8hw9-22v6-9jr9Third Party Advisory
- https://www.npmjs.com/package/%40curveball/a12n-server
- https://github.com/curveball/a12n-server/security/advisories/GHSA-8hw9-22v6-9jr9Third Party Advisory
- https://www.npmjs.com/package/%40curveball/a12n-server
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.