Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2021-43820— Permissions check bypass in Seafile

Quick assessment

Affected
haiwen seafile-server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

海文互知网络技术 Seafile是海文互知网络技术公司的一款开源的企业云盘。该产品具有Markdown WYSIWYG编辑,Wiki,文件标签等功能。 Seafile 存在安全漏洞,该漏洞源于Seafile 文件同步协议中使用同步令牌来授权访问库数据。为了提高性能,令牌缓存在 seaf-server 的内存中。从同步客户端或 SeaDrive 客户端收到令牌后,服务器会检查该令牌是否存在于缓存中。但是,如果令牌存在于缓存中,服务器不会检查它是否与 URL 中的特定库相关联。

CVSS 7.4 · High EPSS 0.96% · P59

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-43820

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Permissions check bypass in Seafile
Source: CVE Program / CVE List V5
Vulnerability Description
Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cached in memory in seaf-server. Upon receiving a token from sync client or SeaDrive client, the server checks whether the token exist in the cache. However, if the token exists in cache, the server doesn't check whether it's associated with the specific library in the URL. This vulnerability makes it possible to use any valid sync token to access data from any **known** library. Note that the attacker has to first find out the ID of a library which it has no access to. The library ID is a random UUID, which is not possible to be guessed. There are no workarounds for this issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5
Vulnerability Title
Seafile 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
海文互知网络技术 Seafile是海文互知网络技术公司的一款开源的企业云盘。该产品具有Markdown WYSIWYG编辑,Wiki,文件标签等功能。 Seafile 存在安全漏洞,该漏洞源于Seafile 文件同步协议中使用同步令牌来授权访问库数据。为了提高性能,令牌缓存在 seaf-server 的内存中。从同步客户端或 SeaDrive 客户端收到令牌后,服务器会检查该令牌是否存在于缓存中。但是,如果令牌存在于缓存中,服务器不会检查它是否与 URL 中的特定库相关联。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
haiwen seafile-server Community Edition < 8.0.8 -

II. Public POCs for CVE-2021-43820

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-43820

登录查看更多情报信息。

Patches & Fixes for CVE-2021-43820 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2021-43820

No comments yet


Leave a comment