Aller au contenu

Fiche vulnérabilité

CVE-2021-27228 : faille critique shinobi shinobi pro (CVSS 9.8)

Description

An issue was discovered in Shinobi through ocean version 1. lib/auth.js has Incorrect Access Control. Valid API Keys are held in an internal JS Object. Therefore an attacker can use JS Proto Method names (such as constructor or hasOwnProperty) to convince the System that the supplied API Key exists in the underlying JS object, and consequently achieve complete access to User/Admin/Super API functions, as demonstrated by a /super/constructor/accounts/list URI.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
22 févr. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • shinobi shinobi pro

Références

Rechercher une autre vulnérabilité dans la base CVE