CVE-2021-3825: Missing Authorization Checks in LiderAhenk
On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lider module in LiderAhenkto a version that resolves this vulnerability.Fixed in 2.1.16
Event History
Frequently Asked Questions
What is CVE-2021-3825?
CVE-2021-3825 is a critical vulnerability in the LiderAhenk software, specifically in the Lider module.
How severe is CVE-2021-3825?
CVE-2021-3825 has a severity rating of 9.6, which is considered critical.
What is the impacted software version of CVE-2021-3825?
The affected software version of CVE-2021-3825 is 2.1.15 and below of the Lider module in LiderAhenk software.
What is the risk of CVE-2021-3825?
CVE-2021-3825 exposes the configurations of the Lider module through an unsecured API, allowing an attacker to obtain valid LDAP credentials.
Are there any fixes or patches available for CVE-2021-3825?
It is recommended to update the LiderAhenk software to a version higher than 2.1.15 to mitigate the vulnerability.