CVE-2021-31797: Race Condition
The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is susceptible to a local host race condition, leading to password disclosure.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-31797?
CVE-2021-31797 is a vulnerability in the user identification mechanism used by CyberArk Credential Provider prior to version 12.1, which is susceptible to a local host race condition, leading to password disclosure.
What is the severity of CVE-2021-31797?
CVE-2021-31797 has a severity rating of 5.1, which is considered medium.
Which software versions are affected by CVE-2021-31797?
CyberArk Credential Provider versions up to but excluding 12.1 are affected by CVE-2021-31797.
How can I fix CVE-2021-31797?
To fix CVE-2021-31797, it is recommended to update CyberArk Credential Provider to version 12.1 or later.
Are there any references regarding CVE-2021-31797?
Yes, here are some references regarding CVE-2021-31797: - [Packet Storm Security](http://packetstormsecurity.com/files/164033/CyberArk-Credential-Provider-Race-Condition-Authorization-Bypass.html) - [Full Disclosure Mailing List](http://seclists.org/fulldisclosure/2021/Sep/2) - [KoreLogic Advisory](https://korelogic.com/Resources/Advisories/KL-001-2021-009.txt)