CVE-2021-43008: High severity adminer vulnerability
Published Apr 5, 2022
·Updated
Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.
Affected Software
2 affected components
Adminer Adminer>=1.12.0<=4.6.2
Debian Debian Linux=9.0
Event History
Apr 5, 2022
CVE Published
via MITRE·01:46 AM
Data Sourced
via MITRE·01:46 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-43008?
CVE-2021-43008 has a medium severity rating due to its ability to allow unauthorized access to sensitive files.
2
How do I fix CVE-2021-43008?
To fix CVE-2021-43008, upgrade Adminer to version 4.6.3 or later.
3
What versions of Adminer are affected by CVE-2021-43008?
Adminer versions 1.12.0 through 4.6.2 are affected by CVE-2021-43008.
4
What type of vulnerability is CVE-2021-43008?
CVE-2021-43008 is categorized as an Improper Access Control vulnerability.
5
Can CVE-2021-43008 lead to any serious impacts?
Yes, CVE-2021-43008 can lead to Arbitrary File Read on the remote server, potentially exposing sensitive data.