CVE-2021-20670: High severity growi vulnerability
Published Mar 10, 2021
·Updated
Improper access control vulnerability in GROWI versions v4.2.2 and earlier allows a remote unauthenticated attacker to read the user's personal information and/or server's internal information via unspecified vectors.
Affected Software
1 affected component
WESEEK GROWI<=4.2.2
Event History
Mar 10, 2021
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20670?
CVE-2021-20670 is classified as a medium-severity vulnerability due to its potential impact on user data security.
2
How do I fix CVE-2021-20670?
To fix CVE-2021-20670, upgrade GROWI to version 4.2.3 or later, which addresses the access control issue.
3
What types of information can be accessed due to CVE-2021-20670?
CVE-2021-20670 allows attackers to read personal information of users and internal server information.
4
Who is affected by CVE-2021-20670?
CVE-2021-20670 affects all GROWI versions up to and including 4.2.2.
5
Can CVE-2021-20670 be exploited remotely?
Yes, CVE-2021-20670 can be exploited by a remote unauthenticated attacker.