Description
Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version could get users names from the LDAP server.
No analysis available yet.
Remediation
Vendor Solution
Update to version 21.3.60
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-23314 | Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version could get users names from the LDAP server. |
References
| Link | Providers |
|---|---|
| https://www.gov.il/en/departments/faq/cve_advisories |
|
History
No history.
Status: PUBLISHED
Assigner: INCD
Published:
Updated: 2024-09-16T16:33:07.338Z
Reserved: 2021-07-12T00:00:00.000Z
Link: CVE-2021-36721
No data.
Status : Modified
Published: 2021-12-14T14:15:09.310
Modified: 2024-11-21T06:13:58.653
Link: CVE-2021-36721
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD