CVE-2021-22957: High severity UI Unifi Protect vulnerability
A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.This vulnerability is fixed in UniFi Protect application Version 1.20.0 and later.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22957?
CVE-2021-22957 is a Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier.
How does CVE-2021-22957 work?
The vulnerability allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user's account.
What is the severity of CVE-2021-22957?
CVE-2021-22957 has a severity rating of 8.8 (high).
How can I fix CVE-2021-22957?
To fix CVE-2021-22957, update UniFi Protect application to Version 1.20.0 or later.
Where can I find more information about CVE-2021-22957?
You can find more information about CVE-2021-22957 in the Security Advisory Bulletin released by Ui at https://community.ui.com/releases/Security-Advisory-Bulletin-021-021/62bd8841-6603-4fee-9dba-73037148f173.