CVE-2021-43829
high · 7.4PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlManager unrestrictly handle upload files in the findings import feature. This vulnerability is capable of uploading dangerous type of file to server leading to XSS attacks and potentially other forms of code injection. Users are advised to update to 1.7.7 as soon as possible. There are no known workarounds for this issue.
7.4
CVSS
59.2%
EPSS (exploit prob.)
99th
EPSS percentile
2021-12-14
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Weaknesses
CWE-434
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| patrowl | patrowlmanager | < 1.7.7 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/Patrowl/PatrowlManager/commit/2287c9715d2e7ef11b44bb0ad4a57727654f2203
- https://github.com/Patrowl/PatrowlManager/security/advisories/GHSA-5hc9-6hq4-2xfx
- https://huntr.dev/bounties/17324785-f83a-4058-ac40-03f2bfa16399/
- https://github.com/Patrowl/PatrowlManager/commit/2287c9715d2e7ef11b44bb0ad4a57727654f2203
- https://github.com/Patrowl/PatrowlManager/security/advisories/GHSA-5hc9-6hq4-2xfx
- https://huntr.dev/bounties/17324785-f83a-4058-ac40-03f2bfa16399/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-43829