CVE-2021-46561: High severity mitre cve services vulnerability
controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user account to an arbitrary new organization, and thereby achieve unintended access within the context of that new organization.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-46561?
CVE-2021-46561 is a vulnerability in the CVE Services API 1.1.1 that allows an organizational administrator to transfer a user account to an arbitrary new organization, resulting in unintended access.
How severe is CVE-2021-46561?
CVE-2021-46561 has a severity rating of 7.2 (high).
How can I fix CVE-2021-46561?
To fix CVE-2021-46561, update to the latest version of the CVE Services API that includes the fix mentioned in the commit 5c50baf3bda28133a3bc90b854765a64fb538304.
What is the CWE ID of CVE-2021-46561?
The CWE ID of CVE-2021-46561 is CWE-863.