CVE-2021-35342

Source
https://cve.org/CVERecord?id=CVE-2021-35342
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-35342.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-35342
Published
2021-08-27T10:15:07.793Z
Modified
2026-07-08T22:14:20.184553Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing invalidation (if the JWT verification cache is enabled).

References

Affected packages

Git / github.com/mendersoftware/useradm

Affected ranges

Type
GIT
Repo
https://github.com/mendersoftware/useradm
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:northern.tech:useradm:1.14.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:northern.tech:useradm:1.13.0:*:*:*:*:*:*:*"
    ],
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "1.14.0"
        },
        {
            "last_affected": "1.14.0"
        },
        {
            "introduced": "1.13.0"
        },
        {
            "last_affected": "1.13.0"
        }
    ]
}

Affected versions

1.*
1.13.0
1.14.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-35342.json"