Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.

Project Subscriptions

Vendors Products
Craftercms Subscribe
Crafter Cms Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-2427 Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.
Github GHSA Github GHSA GHSA-2wr2-8qjq-gh55 Exposure of Resource to Wrong Sphere in org.craftercms:crafter-search
Fixes

Solution

No solution given by the vendor.


Workaround

Disable remote access to crafter-search.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: crafter

Published:

Updated: 2024-09-16T19:15:49.969Z

Reserved: 2021-01-08T00:00:00

Link: CVE-2021-23264

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-02T16:15:07.787

Modified: 2024-11-21T05:51:27.873

Link: CVE-2021-23264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses