CVE-2021-40537: SSRF
Published Sep 8, 2021
·Updated
Server Side Request Forgery (SSRF) vulnerability exists in owncloud/userldap < 0.15.4 in the settings of the userldap app. Administration role is necessary for exploitation.
Affected Software
1 affected component
ownCloud User Ldap<0.15.4
Event History
Sep 8, 2021
CVE Published
via MITRE·05:26 PM
Data Sourced
via MITRE·05:26 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-40537?
CVE-2021-40537 is a Server Side Request Forgery (SSRF) vulnerability in the owncloud/user_ldap < 0.15.4 app.
2
What is the severity of CVE-2021-40537?
CVE-2021-40537 has a severity value of 2.7 (medium).
3
How does the vulnerability in owncloud/user_ldap affect the system?
The vulnerability in owncloud/user_ldap < 0.15.4 allows for Server Side Request Forgery (SSRF) attacks.
4
What is required for exploitation of CVE-2021-40537?
Exploiting CVE-2021-40537 requires the administration role in owncloud/user_ldap.
5
Where can I find more information about CVE-2021-40537?
You can find more information about CVE-2021-40537 at the following link: https://owncloud.com/security-advisories/cve-2021-40537/