First published: Thu Oct 14 2021(Updated: )
In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIImage.i4".
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yellowfinbi Yellowfin | <9.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36389 is an Insecure Direct Object Reference vulnerability in Yellowfin before 9.6.1, which allows attackers to enumerate and download uploaded images.
An attacker can exploit CVE-2021-36389 by sending a specially crafted HTTP GET request to the page "MIImage.i4".
Yellowfin versions up to and excluding 9.6.1 are affected by CVE-2021-36389.
CVE-2021-36389 has a severity of 7.5 (High).
To fix CVE-2021-36389, upgrade Yellowfin to version 9.6.1 or later.