First published: Mon Dec 06 2021(Updated: )
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing an insecure Sudo rule.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kaseya Unitrends Backup Software | >=10.0<10.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43043 has a medium severity rating due to the potential for unauthorized access to sensitive files.
To fix CVE-2021-43043, upgrade your Kaseya Unitrends Backup Appliance to version 10.5.5 or later.
CVE-2021-43043 affects Kaseya Unitrends Backup Appliance versions prior to 10.5.5.
The impact of CVE-2021-43043 is that the apache user can read arbitrary files, potentially exposing sensitive information.
There are no specific workarounds for CVE-2021-43043; updating to the latest version is the recommended action.