CVE-2021-30141: High severity friendica vulnerability
DISPUTED Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as demonstrated by an attempted access to an array offset on a value of type null, and excessive memory consumption. NOTE: the vendor states "the feature still requires a valid authentication cookie even if the route is accessible to non-logged users."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-30141?
CVE-2021-30141 has a severity rating that needs to be assessed based on potential impacts, but it is considered a security concern due to unauthorized access by anonymous users.
How do I fix CVE-2021-30141?
To mitigate CVE-2021-30141, ensure that access to the settings/userexport feature is restricted to authenticated users only.
What impact does CVE-2021-30141 have on my system?
CVE-2021-30141 can lead to unauthorized access and excessive memory consumption, potentially affecting system performance.
Is CVE-2021-30141 actively being exploited?
There are no current reports of active exploitation specifically targeting CVE-2021-30141, but vulnerabilities of this nature typically carry risks.
Which versions of Friendica are affected by CVE-2021-30141?
Friendica versions up to and including 2021.01 are affected by CVE-2021-30141.