Abstrium Pydio Cells User Creation access control
Published May 30, 2023
8.8
HIGHCVSS 3.1
EPSS 0.81%
Description
A vulnerability classified as critical has been found in Abstrium Pydio Cells 4.2.0. This affects an unknown part of the component User Creation Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-230211.
Affected products
-
- Version 4.2.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Abstrium | Pydio Cells | n/a |
|
- 4.2.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-34419 Advisory
- https://popalltheshells.medium.com/multiple-cves-affecting-pydio-cells-4-2-0-321e7e4712be exploitThird Party Advisory
- https://pydio.com/en/community/releases/pydio-cells/pydio-cells-enterprise-421 patchRelease Notes
- https://vuldb.com/?ctiid.230211 signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry
- https://vuldb.com/?id.230211 vdb-entrytechnical-descriptionPermissions RequiredThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-34419 | Advisory | |
| https://popalltheshells.medium.com/multiple-cves-affecting-pydio-cells-4-2-0-321e7e4712be | exploitThird Party Advisory | |
| https://pydio.com/en/community/releases/pydio-cells/pydio-cells-enterprise-421 | patchRelease Notes | |
| https://vuldb.com/?ctiid.230211 | signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?id.230211 | vdb-entrytechnical-descriptionPermissions RequiredThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.