CVE-2021-36383
Summary
| CVE | CVE-2021-36383 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-12 14:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacker changes the permission field from none to admin. The attacker gains access to data sets such as VMs, Backups, Audit, Users, and Groups. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Xen-orchestra | Xo-server | All | All | All | All |
| Application | Xen-orchestra | Xo-web | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| XEN Orchestra privilege escalation via websockets · Issue #5712 · vatesfr/xen-orchestra · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995642 NodeJs (Npm) Security Update for xo-server (GHSA-grvm-gcqf-gh8q)