Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2021-43781
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Permissions not properly checked in Invenio-Drafts-Resources
Source: NVD (National Vulnerability Database)
Vulnerability Description
Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable in a default installation of InvenioRDM. An authenticated a user is able via REST API calls to publish draft records of other users if they know the record identifier and the draft validates (e.g. all require fields filled out). An attacker is not able to modify the data in the record, and thus e.g. *cannot* change a record from restricted to public. The problem is patched in Invenio-Drafts-Resources v0.13.7 and 0.14.6, which is part of InvenioRDM v6.0.1 and InvenioRDM v7.0 respectively.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
授权机制缺失
Source: NVD (National Vulnerability Database)
Vulnerability Title
Invenio-Drafts-Resources 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Invenio-Drafts-Resources是一个 Invenio 的提交/存入模块。用于研究数据管理。 Invenio-Drafts-Resources 0.13.7 和 0.14.6 之前的版本存在安全漏洞,该漏洞源于受影响产品无法正确检查权限。该漏洞可在 InvenioRDM 的默认安装中利用。如果其他用户知道记录标识符并且草稿经过验证(例如,所有需要填写的字段),则经过身份验证的用户能够通过 REST API 调用发布其他用户的草稿记录。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
inveniosoftwareinvenio-drafts-resources < 0.13.7 -
II. Public POCs for CVE-2021-43781
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2021-43781
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2021-43781

No comments yet


Leave a comment