{"api_version":"1","generated_at":"2026-07-23T19:19:13+00:00","cve":"CVE-2021-20791","urls":{"html":"https://cve.report/CVE-2021-20791","api":"https://cve.report/api/cve/CVE-2021-20791.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-20791","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-20791"},"summary":{"title":"CVE-2021-20791","description":"Improper access control vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to bypass access restriction and to exchange unauthorized files between the local environment and the isolated environment or settings of the web browser via unspecified vectors.","state":"PUBLIC","assigner":"vultures@jpcert.or.jp","published_at":"2021-09-17 02:15:00","updated_at":"2022-07-12 17:42:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://jvn.jp/en/jp/JVN81658818/index.html","name":"https://jvn.jp/en/jp/JVN81658818/index.html","refsource":"MISC","tags":[],"title":"JVN#81658818: Multiple vulnerabilities in RevoWorks Browser","mime":"text/xml","httpstatus":"200","archivestatus":"404"},{"url":"https://jscom.jp/news-20210910_2/","name":"https://jscom.jp/news-20210910_2/","refsource":"MISC","tags":[],"title":"【重要】RevoWorks Browser の複数の脆弱性（CVE-2021-20790、CVE-2021-20791）に関する注意喚起 | ジェイズ・コミュニケーション","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-20791","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-20791","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"20791","vulnerable":"1","versionEndIncluding":"2.1.230","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jscom","cpe5":"revoworks_browser","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-20791","ASSIGNER":"vultures@jpcert.or.jp","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"J’s Communication Co., Ltd.","product":{"product_data":[{"product_name":"RevoWorks Browser","version":{"version_data":[{"version_value":"2.1.230 and earlier"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper Access Control"}]}]},"references":{"reference_data":[{"url":"https://jscom.jp/news-20210910_2/","refsource":"MISC","name":"https://jscom.jp/news-20210910_2/"},{"url":"https://jvn.jp/en/jp/JVN81658818/index.html","refsource":"MISC","name":"https://jvn.jp/en/jp/JVN81658818/index.html"}]},"description":{"description_data":[{"lang":"eng","value":"Improper access control vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to bypass access restriction and to exchange unauthorized files between the local environment and the isolated environment or settings of the web browser via unspecified vectors."}]}},"nvd":{"publishedDate":"2021-09-17 02:15:00","lastModifiedDate":"2022-07-12 17:42:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":9.3,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":4.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:jscom:revoworks_browser:*:*:*:*:*:*:*:*","versionStartIncluding":"2.1.197","versionEndIncluding":"2.1.230","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"20791","Ordinal":"194836","Title":"CVE-2021-20791","CVE":"CVE-2021-20791","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"20791","Ordinal":"1","NoteData":"Improper access control vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to bypass access restriction and to exchange unauthorized files between the local environment and the isolated environment or settings of the web browser via unspecified vectors.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"20791","Ordinal":"2","NoteData":"2021-09-16","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"20791","Ordinal":"3","NoteData":"2021-09-16","Type":"Other","Title":"Modified"}]}}}