CVE-2021-43829: Unrestricted Upload of Files in Patrowl
PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlManager unrestrictly handle upload files in the findings import feature. This vulnerability is capable of uploading dangerous type of file to server leading to XSS attacks and potentially other forms of code injection. Users are advised to update to 1.7.7 as soon as possible. There are no known workarounds for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43829?
CVE-2021-43829 has a medium severity level due to the potential for XSS attacks.
How do I fix CVE-2021-43829?
To fix CVE-2021-43829, update PatrowlManager to version 1.7.7 or later.
What type of vulnerability is CVE-2021-43829?
CVE-2021-43829 is a vulnerability related to unrestricted file uploads that can lead to cross-site scripting (XSS) attacks.
What versions are affected by CVE-2021-43829?
CVE-2021-43829 affects all versions of PatrowlManager prior to 1.7.7.
Can CVE-2021-43829 be exploited remotely?
Yes, CVE-2021-43829 can be exploited remotely, allowing attackers to upload malicious files.