CVE-2021-3309: High severity Wekan project Wekan vulnerability
Published Jan 26, 2021
·Updated
packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Certification Authority trust store,
Affected Software
1 affected component
Wekan project Wekan<4.87
Remediation
Event History
Jan 26, 2021
CVE Published
via MITRE·08:13 PM
Data Sourced
via MITRE·08:13 PM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-3309?
CVE-2021-3309 is a vulnerability in Wekan before version 4.87 that allows processing of unauthorized connections.
2
What is the severity of CVE-2021-3309?
CVE-2021-3309 has a severity score of 8.1 (high).
3
What software versions are affected by CVE-2021-3309?
Versions up to and exclusive of 4.87 of Wekan are affected by CVE-2021-3309.
4
How can I fix CVE-2021-3309?
To fix CVE-2021-3309, update Wekan to version 4.87 or higher.
5
Where can I find more information about CVE-2021-3309?
You can find more information about CVE-2021-3309 on the Wekan GitHub repository and in the release notes for version 4.87.