Description
Single Connect does not perform an authorization check when using the "sc-assigned-credential-ui" module. A remote attacker could exploit this vulnerability to modify users permissions. The exploitation of this vulnerability might allow a remote attacker to delete permissions from other users without authenticating.
No analysis available yet.
Remediation
Vendor Solution
Single Connect should be updated to the latest version provided by the vendor.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-31599 | Single Connect does not perform an authorization check when using the "sc-assigned-credential-ui" module. A remote attacker could exploit this vulnerability to modify users permissions. The exploitation of this vulnerability might allow a remote attacker to delete permissions from other users without authenticating. |
References
| Link | Providers |
|---|---|
| https://www.usom.gov.tr/bildirim/tr-22-0093 |
|
History
Tue, 17 Sep 2024 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Single Connect does not perform an authorization check when using the "sc-assigned-credential-ui" module. A remote attacker could exploit this vulnerability to modify users permissions. The exploitation of this vulnerability might allow a remote attacker to delete permissions from other users without authenticating. | Single Connect does not perform an authorization check when using the "sc-assigned-credential-ui" module. A remote attacker could exploit this vulnerability to modify users permissions. The exploitation of this vulnerability might allow a remote attacker to delete permissions from other users without authenticating. |
Status: PUBLISHED
Assigner: TR-CERT
Published:
Updated: 2024-09-17T00:40:52.613Z
Reserved: 2021-12-10T00:00:00.000Z
Link: CVE-2021-44795
No data.
Status : Modified
Published: 2022-01-27T13:15:08.007
Modified: 2024-11-21T06:31:34.143
Link: CVE-2021-44795
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD