CVE-2021-23264: Transmission of Private Resources into a New Sphere ('Resource Leak') and Exposure of Resource to Wrong Sphere in Crafter Search
Published Dec 2, 2021
·Updated
Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.
Affected Software
1 affected component
CrafterCMS Crafter Cms>=3.1.0<3.1.15
Event History
Dec 2, 2021
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-23264?
The severity of CVE-2021-23264 is critical with a CVSS score of 9.1.
2
What software is affected by CVE-2021-23264?
The software affected by CVE-2021-23264 is Crafter CMS versions 3.1.0 to 3.1.15.
3
What can unauthenticated remote attackers do with CVE-2021-23264?
Unauthenticated remote attackers can create, view, and delete search indexes on installations where crafter-search is not protected.
4
How can I protect my installation from CVE-2021-23264?
To protect your installation, make sure to protect crafter-search and implement authentication for remote access.
5
Is there any documentation available for CVE-2021-23264?
Yes, you can refer to the official advisory for more information on CVE-2021-23264: https://docs.craftercms.org/en/3.1/security/advisory.html#cv-2021120107