CVE-2021-25930
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to CSRF, due to no CSRF protection, and since there is no validation of an existing user name while renaming a user. As a result, privileges of the renamed user are being overwritten by the old user and the old user is being deleted from the user list.
En OpenNMS Horizon, versiones opennms-1-0-stable hasta opennms-27.1.0-1; OpenNMS Meridian, versiones meridian-foundation-2015.1.0-1 hasta meridian-foundation-2019.1.18-1; versiones meridian-foundation-2020.1.0-1 hasta meridian-foundation-2020.1.6-1, son vulnerables a ataques de tipo CSRF, debido a que no presentan protección de tipo CSRF, y dado que no presenta comprobación de un nombre de usuario existente al cambiar el nombre de un usuario. Como resultado, los privilegios del usuario renombrado están siendo sobrescritos por el usuario anterior y el usuario anterior está siendo eliminado de la lista de usuarios
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-22 CVE Reserved
- 2021-05-20 CVE Published
- 2023-12-25 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25930 | 2024-08-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Opennms Search vendor "Opennms" | Horizon Search vendor "Opennms" for product "Horizon" | >= 1.0 < 27.1.1 Search vendor "Opennms" for product "Horizon" and version " >= 1.0 < 27.1.1" | - |
Affected
| ||||||
Opennms Search vendor "Opennms" | Meridian Search vendor "Opennms" for product "Meridian" | >= 2015.1.0 < 2019.1.19 Search vendor "Opennms" for product "Meridian" and version " >= 2015.1.0 < 2019.1.19" | - |
Affected
| ||||||
Opennms Search vendor "Opennms" | Meridian Search vendor "Opennms" for product "Meridian" | >= 2020.1.0 < 2020.1.7 Search vendor "Opennms" for product "Meridian" and version " >= 2020.1.0 < 2020.1.7" | - |
Affected
|