CVE-2021-3049: Cortex XSOAR: Improper Authorization of Incident Investigations Vulnerability
An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part of. This issue impacts: All Cortex XSOAR 5.5.0 builds; Cortex XSOAR 6.1.0 builds earlier than 12099345. This issue does not impact Cortex XSOAR 6.2.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto Networks Cortex XSOARto a version that resolves this vulnerability.Fixed in 6.1.0Patch 12099345
Event History
Frequently Asked Questions
What is CVE-2021-3049?
CVE-2021-3049 is an improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server.
How does CVE-2021-3049 impact Palo Alto Networks Cortex XSOAR?
CVE-2021-3049 enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part of.
What is the severity of CVE-2021-3049?
The severity of CVE-2021-3049 is medium with a CVSS score of 4.3.
Which versions of Palo Alto Networks Cortex XSOAR are affected by CVE-2021-3049?
CVE-2021-3049 impacts all versions of Palo Alto Networks Cortex XSOAR 5.5.0, 6.1.0, and their respective subversions.
How can I fix CVE-2021-3049?
To fix CVE-2021-3049, update your Palo Alto Networks Cortex XSOAR server to a patched version.