{"api_version":"1","generated_at":"2026-07-23T13:28:10+00:00","cve":"CVE-2021-2322","urls":{"html":"https://cve.report/CVE-2021-2322","api":"https://cve.report/api/cve/CVE-2021-2322.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-2322","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-2322"},"summary":{"title":"CVE-2021-2322","description":"Vulnerability in OpenGrok (component: Web App). Versions that are affected are 1.6.7 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise OpenGrok. Successful attacks of this vulnerability can result in takeover of OpenGrok. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","state":"PUBLIC","assigner":"secalert_us@oracle.com","published_at":"2021-06-23 23:15:00","updated_at":"2021-06-30 00:43:00"},"problem_types":["CWE-91"],"metrics":[],"references":[{"url":"https://www.oracle.com/security-alerts/oracle-open-source-cves-outside-other-oracle-public-documents.html","name":"https://www.oracle.com/security-alerts/oracle-open-source-cves-outside-other-oracle-public-documents.html","refsource":"MISC","tags":[],"title":"CVEs for Oracle open source projects not published in other Oracle public documents","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-2322","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-2322","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"2322","vulnerable":"1","versionEndIncluding":"1.6.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"opengrok","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-2322","qid":"690753","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for opengrok (1135e939-62b4-11ec-b8e2-1c1b0d9ea7e6)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ASSIGNER":"secalert_us@oracle.com","ID":"CVE-2021-2322","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"OpenGrok","version":{"version_data":[{"version_value":"1.6.7 and prior","version_affected":"="}]}}]},"vendor_name":"Oracle Corporation"}]}},"description":{"description_data":[{"lang":"eng","value":"Vulnerability in OpenGrok (component: Web App). Versions that are affected are 1.6.7 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise OpenGrok. Successful attacks of this vulnerability can result in takeover of OpenGrok. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)."}]},"impact":{"cvss":{"baseScore":"8.8","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise OpenGrok.  Successful attacks of this vulnerability can result in takeover of OpenGrok."}]}]},"references":{"reference_data":[{"url":"https://www.oracle.com/security-alerts/oracle-open-source-cves-outside-other-oracle-public-documents.html","refsource":"MISC","name":"https://www.oracle.com/security-alerts/oracle-open-source-cves-outside-other-oracle-public-documents.html"}]}},"nvd":{"publishedDate":"2021-06-23 23:15:00","lastModifiedDate":"2021-06-30 00:43:00","problem_types":["CWE-91"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:oracle:opengrok:*:*:*:*:*:*:*:*","versionEndIncluding":"1.6.7","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"2322","Ordinal":"193431","Title":"CVE-2021-2322","CVE":"CVE-2021-2322","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"2322","Ordinal":"1","NoteData":"Vulnerability in OpenGrok (component: Web App). Versions that are affected are 1.6.7 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise OpenGrok. Successful attacks of this vulnerability can result in takeover of OpenGrok. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","Type":"Description","Title":null},{"CveYear":"2021","CveId":"2322","Ordinal":"2","NoteData":"2021-06-23","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"2322","Ordinal":"3","NoteData":"2021-06-23","Type":"Other","Title":"Modified"}]}}}