Vulnerability Database
Blog
FAQ
Docs
CVE-2021-3964
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2021-3964
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3964.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-3964
Aliases
GHSA-gwpx-q2h9-wxgx
Published
2021-12-01T12:15:07Z
Modified
2024-05-14T10:33:05.893627Z
Severity
5.9 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS Calculator
Summary
[none]
Details
elgg is vulnerable to Authorization Bypass Through User-Controlled Key
References
https://huntr.dev/bounties/a4df45d6-b739-4299-967f-c960b569383a
https://github.com/elgg/elgg/commit/d9fcad76ee380ea17edd61d13d0f87828ea3f744
Affected packages
Git
/
github.com/elgg/elgg
Affected ranges
Type
GIT
Repo
https://github.com/elgg/elgg
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
d9fcad76ee380ea17edd61d13d0f87828ea3f744
Affected versions
1.*
1.1
1.10.0
1.10.0-rc.1
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.10.6
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.12.0
1.12.1
1.12.10
1.12.11
1.12.12
1.12.13
1.12.14
1.12.15
1.12.16
1.12.17
1.12.18
1.12.2
1.12.3
1.12.4
1.12.5
1.12.6
1.12.7
1.12.8
1.12.9
1.1rc1
1.2
1.5.0
1.5.0rc1
1.5.0rc2
1.7.0b1
1.8.0
1.8.0.1
1.8.0b1
1.8.0b2
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.1b1
1.8.2
1.8.20
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.0-rc.1
1.9.0-rc.2
1.9.0-rc.3
1.9.0-rc.4
1.9.0-rc.5
1.9.0-rc.6
1.9.0-rc.7
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
2.*
2.0.0
2.0.0-alpha.1
2.0.0-alpha.2
2.0.0-alpha.3
2.0.0-beta.1
2.0.0-beta.2
2.0.0-beta.3
2.0.0-rc.1
2.0.0-rc.2
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0-rc.1
2.2.1
2.2.2
2.2.3
2.2.4
2.3.0
2.3.0-rc.1
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
3.*
3.0.0
3.0.0-beta.1
3.0.0-beta.2
3.0.0-beta.3
3.0.0-rc.1
3.0.0-rc.2
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.3.0
3.3.1
3.3.10
3.3.11
3.3.12
3.3.13
3.3.14
3.3.15
3.3.16
3.3.17
3.3.18
3.3.19
3.3.2
3.3.20
3.3.21
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
CVE-2021-3964 - OSV