CVE-2021-27228
Summary
| CVE | CVE-2021-27228 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-22 17:15:00 UTC |
| Updated | 2021-02-26 18:23:00 UTC |
| Description | An issue was discovered in Shinobi through ocean version 1. lib/auth.js has Incorrect Access Control. Valid API Keys are held in an internal JS Object. Therefore an attacker can use JS Proto Method names (such as constructor or hasOwnProperty) to convince the System that the supplied API Key exists in the underlying JS object, and consequently achieve complete access to User/Admin/Super API functions, as demonstrated by a /super/constructor/accounts/list URI. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Shinobi | Shinobi Pro | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Critical Fixes and Updates (!286) · Merge Requests · Shinobi Systems / Shinobi · GitLab | MISC | gitlab.com | Patch, Third Party Advisory |
| Shinobi - Simple CCTV and NVR Solution - Home | MISC | shinobi.video | Product |
| Tags · Shinobi Systems / Shinobi · GitLab | MISC | gitlab.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.