CVE-2021-21471
Summary
| CVE | CVE-2021-21471 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-12 15:15:00 UTC |
| Updated | 2021-01-15 14:44:00 UTC |
| Description | In CLA-Assistant, versions before 2.8.5, due to improper access control an authenticated user could access API endpoints which are not intended to be used by the user. This could impact the integrity of the application. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Cla-assistant | All | All | All | All |
| Application | Sap | Cla-assistant | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Improper API Access Control in CLA assistant · Advisory · cla-assistant/cla-assistant · GitHub | CONFIRM | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.