CVE-2021-29024: High severity InvoicePlane InvoicePlane vulnerability
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
InvoicePlaneto a version that resolves this vulnerability.Fixed in 1.5.11 - Configuration
Reconfigure the web server hosting InvoicePlane to require authentication for any directory listing and file download endpoints so that unauthenticated users cannot list or download private files (misconfiguration in InvoicePlane 1.5.11 allows unauthenticated access).
InvoicePlane (web server hosting) Authentication requirement for directory listing and file download = required
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29024?
CVE-2021-29024 is classified as a high severity vulnerability due to the potential for unauthorized access to sensitive files.
How do I fix CVE-2021-29024?
To fix CVE-2021-29024, ensure your web server is properly configured to prevent unauthorized directory listing and file downloads.
What are the potential impacts of CVE-2021-29024?
The impacts of CVE-2021-29024 include unauthorized access to private files and sensitive information by attackers.
Who is affected by CVE-2021-29024?
CVE-2021-29024 affects users of InvoicePlane version 1.5.11 with misconfigured web server settings.
Is CVE-2021-29024 remotely exploitable?
Yes, CVE-2021-29024 is remotely exploitable due to the lack of authentication required to access the vulnerable directory.