One Article Review

Accueil - L'article:
Source CVE.webp CVE Liste
Identifiant 3753827
Date de publication 2021-12-06 18:15:08 (vue: 2021-12-06 20:06:20)
Titre CVE-2021-43781
Texte Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable in a default installation of InvenioRDM. An authenticated a user is able via REST API calls to publish draft records of other users if they know the record identifier and the draft validates (e.g. all require fields filled out). An attacker is not able to modify the data in the record, and thus e.g. *cannot* change a record from restricted to public. The problem is patched in Invenio-Drafts-Resources v0.13.7 and 0.14.6, which is part of InvenioRDM v6.0.1 and InvenioRDM v7.0 respectively.
Envoyé Oui
Condensat *cannot* 2021 43781 able all api attacker authenticated calls change check cve data default does draft drafts exploitable fields filled framework from identifier installation invenio inveniordm know management modify module not other out part patched permissions prior problem properly public publish published record records require research resources respectively rest restricted software submission/deposit thus user users validates versions vulnerability when which
Tags Vulnerability
Stories
Notes
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: