First published: Wed Jan 26 2022(Updated: )
controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user account to an arbitrary new organization, and thereby achieve unintended access within the context of that new organization.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitre CVE Services | =1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46561 is a vulnerability in the CVE Services API 1.1.1 that allows an organizational administrator to transfer a user account to an arbitrary new organization, resulting in unintended access.
CVE-2021-46561 has a severity rating of 7.2 (high).
To fix CVE-2021-46561, update to the latest version of the CVE Services API that includes the fix mentioned in the commit 5c50baf3bda28133a3bc90b854765a64fb538304.
The CWE ID of CVE-2021-46561 is CWE-863.