CVE-2021-41325: Medium severity Pydio Cells vulnerability
Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via the profile parameter. (In addition, such users can be granted several admin permissions via the Roles parameter.)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-41325?
CVE-2021-41325 refers to the vulnerability where broken access control in Pydio Cells 2.2.9 allows remote anonymous users to create standard users and grant admin permissions.
How severe is CVE-2021-41325?
CVE-2021-41325 has a severity keyword of 'medium' and a severity value of 6.5.
How can I fix the CVE-2021-41325 vulnerability?
To fix the CVE-2021-41325 vulnerability, upgrade to Pydio Cells version 2.2.12 or higher.
Where can I find more information about CVE-2021-41325?
You can find more information about CVE-2021-41325 at the following references: [Reference 1](https://charonv.net/Pydio-Broken-Access-Control/), [Reference 2](https://github.com/pydio/cells/releases/tag/v2.2.12), [Reference 3](https://pydio.com/fr/community/releases/pydio-cells/pydio-cells-enterprise-2212)