First published: Thu Feb 11 2021(Updated: )
Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adminer Adminer | >=4.0.0<4.7.9 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21311 is considered to be a medium severity vulnerability due to its impact on server-side request forgery.
To fix CVE-2021-21311, upgrade Adminer to version 4.7.9 or later.
Adminer versions from 4.0.0 to 4.7.8 are affected by CVE-2021-21311.
CVE-2021-21311 can be present in Debian Linux 9.0 if an affected version of Adminer is used.
CVE-2021-21311 is categorized as a server-side request forgery vulnerability.