7.4

CVE-2021-29487

Authentication bypass in Octobercms

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vulnerability to bypass authentication and takeover of and user account on an October CMS server. The vulnerability is exploitable by unauthenticated users via a specially crafted request. This only affects frontend users and the attacker must obtain a Laravel secret key for cookie encryption and signing in order to exploit this vulnerability. The issue has been patched in Build 472 and v1.1.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OctobercmsOctober Version >= 1.0.471 < 1.0.472
OctobercmsOctober Version >= 1.1.1 < 1.1.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.9% 0.548
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
security-advisories@github.com 7.4 2.2 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://github.com/octobercms/library/commit/016a297b1bec55d2e53bc889458ed2cb5c3e9374
Patch
Third Party Advisory
https://github.com/octobercms/library/commit/5bd1a28140b825baebe6becd4f7562299d3de3b9
Patch
Third Party Advisory
https://github.com/octobercms/october/security/advisories/GHSA-h76r-vgf3-j6w5
Patch
Third Party Advisory