CVE-2021-20306: Medium severity red hat decision manager vulnerability
A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the name of Ruleflow Groups from other projects, despite the user not having access to those projects. The highest threat from this vulnerability is to confidentiality.
Other sources
Ruleflow Groups from other projects displayed on BPMN editor despite user having no access to those projects
https://issues.redhat.com/browse/JBPM-9662
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2021-20306.
What is the severity rating of CVE-2021-20306?
The severity rating of CVE-2021-20306 is medium, with a value of 4.3.
What is the affected software for CVE-2021-20306?
The affected software for CVE-2021-20306 includes jBPM 7.51.0.Final, Redhat Descision Manager 7.0, Redhat Jbpm 7.51.0, and Redhat Process Automation 7.0.
What is the impact of CVE-2021-20306?
The highest threat from this vulnerability is to confidentiality.
Is there a fix available for CVE-2021-20306?
Yes, a fix is available for CVE-2021-20306. Please refer to the referenced link for more information.