CVE-2021-41251
Summary
| CVE | CVE-2021-41251 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-05 23:15:00 UTC |
| Updated | 2021-11-15 16:31:00 UTC |
| Description | @sap-cloud-sdk/core contains the core functionality of the SAP Cloud SDK as well as the SAP Business Technology Platform abstractions. This affects applications on SAP Business Technology Platform that use the SAP Cloud SDK and enabled caching of destinations. In affected versions and in some cases, when user information was missing, destinations were cached without user information, allowing other users to retrieve the same destination with its permissions. By default, destination caching is disabled. The security for caching has been increased. The changes are released in version 1.52.0. Users unable to upgrade are advised to disable destination caching (it is disabled by default). |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix: wrong token for cache by FrankEssenberger · Pull Request #1769 · SAP/cloud-sdk-js · GitHub | MISC | github.com | |
| Possibility to elevate privileges or get unauthorized access to data · Advisory · SAP/cloud-sdk-js · GitHub | CONFIRM | github.com | |
| Fix: destination cache vulnerablity by jjtang1985 · Pull Request #1770 · SAP/cloud-sdk-js · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980195 Nodejs (npm) Security Update for @sap-cloud-sdk/core (GHSA-gp2f-254m-rh32)