{"api_version":"1","generated_at":"2026-07-23T15:40:28+00:00","cve":"CVE-2021-25991","urls":{"html":"https://cve.report/CVE-2021-25991","api":"https://cve.report/api/cve/CVE-2021-25991.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-25991","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-25991"},"summary":{"title":"CVE-2021-25991","description":"In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.","state":"PUBLIC","assigner":"vulnerabilitylab@whitesourcesoftware.com","published_at":"2021-12-29 09:15:00","updated_at":"2022-01-10 16:29:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://github.com/ifmeorg/ifme/commit/d1f570c458d41667df801fc9c40a18b181a2d923","name":"N/A","refsource":"CONFIRM","tags":[],"title":"[#2052] Fix improper access control leads to admin self-banning · ifmeorg/ifme@d1f570c · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25991","name":"N/A","refsource":"MISC","tags":[],"title":"CVE-2021-25991 | WhiteSource Vulnerability Database","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-25991","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-25991","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"WhiteSource Vulnerability Research Team (WVR)","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"25991","vulnerable":"1","versionEndIncluding":"7.32","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"if-me","cpe5":"ifme","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"vulnerabilitylab@whitesourcesoftware.com","DATE_PUBLIC":"2021-12-27T08:22:00.000Z","ID":"CVE-2021-25991","STATE":"PUBLIC","TITLE":"ifme - Improper Access Control leads to admin deactivation"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"ifme","version":{"version_data":[{"version_affected":">=","version_value":"v5.0.0"},{"version_affected":"<=","version_value":"v7.32"}]}}]},"vendor_name":"ifmeorg"}]}},"credit":[{"lang":"eng","value":"WhiteSource Vulnerability Research Team (WVR)"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":5.7,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-284 Improper Access Control"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://github.com/ifmeorg/ifme/commit/d1f570c458d41667df801fc9c40a18b181a2d923","name":"https://github.com/ifmeorg/ifme/commit/d1f570c458d41667df801fc9c40a18b181a2d923"},{"refsource":"MISC","url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25991","name":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25991"}]},"solution":[{"lang":"eng","value":"Update version to v7.32.1 or later"}],"source":{"advisory":"https://www.whitesourcesoftware.com/vulnerability-database/","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-12-29 09:15:00","lastModifiedDate":"2022-01-10 16:29:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.3,"baseSeverity":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.9},"severity":"MEDIUM","exploitabilityScore":6.8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:if-me:ifme:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0","versionEndIncluding":"7.32","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"25991","Ordinal":"200918","Title":"CVE-2021-25991","CVE":"CVE-2021-25991","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"25991","Ordinal":"1","NoteData":"In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"25991","Ordinal":"2","NoteData":"2021-12-29","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"25991","Ordinal":"3","NoteData":"2021-12-29","Type":"Other","Title":"Modified"}]}}}