CVE-2021-43828: Improper Privilege Management in Patrowl
PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) has been found in PatrowlManager. All imports findings file is placed under /media/imports/<ownerid>/<tmpfile> In that, ownerid is predictable and tmpfile is in format of import<ownderid><timecreated>, for example: import11639213059582.json This filename is predictable and allows anyone without logging in to download all finding import files This vulnerability is capable of allowing unlogged in users to download all finding imports file. Users are advised to update to 1.7.7 as soon as possible. There are no known workarounds.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43828?
CVE-2021-43828 has been classified with a medium severity level due to its improper privilege management that may lead to unauthorized access.
How do I fix CVE-2021-43828?
To fix CVE-2021-43828, update PatrowlManager to version 1.7.7 or later to mitigate the identified improper privilege management vulnerability.
What versions of PatrowlManager are affected by CVE-2021-43828?
PatrowlManager versions prior to 1.7.7 are affected by the vulnerability identified in CVE-2021-43828.
What kind of vulnerability is CVE-2021-43828?
CVE-2021-43828 is an improper privilege management vulnerability, specifically an IDOR (Insecure Direct Object Reference) issue.
Is CVE-2021-43828 exploitable remotely?
Yes, CVE-2021-43828 may be exploitable remotely, allowing an attacker to bypass access controls.