| 
[Japanese]
 | 
JVNDB-2021-000109
 | 
Multiple missing authorization vulnerabilities in WordPress Plugin "Advanced Custom Fields"
 | 
 
WordPress Plugin "Advanced Custom Fields" provided by Delicious Brains contains multiple missing authorization vulnerabilities listed below. 
 
* Missing authorization related to database browsing (CWE-862) - CVE-2021-20865 
* Missing authorization related to user list obtaining (CWE-862) - CVE-2021-20866 
* Missing authorization related to field group movement (CWE-862) - CVE-2021-20867 
 
Keitaro Yamazaki of Ierae Security, Inc reported these vulnerabilities to IPA. 
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
 
 | 
 
  CVSS V3 Severity: Base Metrics 4.3 (Medium) [IPA Score]
  
    - Attack Vector: Network
 
    - Attack Complexity: Low
 
    - Privileges Required: Low
 
    - User Interaction: None
 
    - Scope: Unchanged
 
    - Confidentiality Impact: Low
 
    - Integrity Impact: None
 
    - Availability Impact: None
 
   
 
  CVSS V2 Severity: Base Metrics 4.0 (Medium) [IPA Score]
  
    - Access Vector: Network
 
    - Access Complexity: Low
 
    - Authentication: Single Instance
 
    - Confidentiality Impact: Partial
 
    - Integrity Impact: None
 
    - Availability Impact: None
 
   
 
 
  
The above CVSS base scores have been assigned for CVE-2021-20865
 
 
  | 
 
 
 CVSS V3 Severity: Base Metrics 4.3 (Medium) [IPA Score]
- Attack Vector: Network
 
- Attack Complexity: Low
 
- Privileges Required: Low
 
- User Interaction: None
 
- Scope: Unchanged
 
- Confidentiality Impact: Low
 
- Integrity Impact: None
 
- Availability Impact: None
 
 
 
CVSS V2 Severity:Base Metrics 4.0 (Medium) [IPA Score]
- Access Vector: Network
 
- Access Complexity: Low
 
- Authentication: Single
 
- Confidentiality Impact: Partial
 
- Integrity Impact: None
 
- Availability Impact: None
 
 
 
 
The above CVSS base scores have been assigned for CVE-2021-20866
  
 | 
 
 
 CVSS V3 Severity: Base Metrics 4.3 (Medium) [IPA Score]
- Attack Vector: Network
 
- Attack Complexity: Low
 
- Privileges Required: Low
 
- User Interaction: None
 
- Scope: Unchanged
 
- Confidentiality Impact: None
 
- Integrity Impact: Low
 
- Availability Impact: None
 
 
 
CVSS V2 Severity:Base Metrics 4.0 (Medium) [IPA Score]
- Access Vector: Network
 
- Access Complexity: Low
 
- Authentication: Single
 
- Confidentiality Impact: None
 
- Integrity Impact: Partial
 
- Availability Impact: None
 
 
 
 
The above CVSS base scores have been assigned for CVE-2021-20867
  
 | 
 
	
 
 | 
 
	Delicious Brains
	
		- Advanced Custom Fields 5.11 prior to 5.11
 
		- Advanced Custom Fields Pro 5.11 prior to 5.11
 
		 
 
 | 
 
	
 
 | 
 
A user with a lower level of authority than Editor role (such as Subscriber, Contributor, Author roles) may: 
* View the information on the database without the access permission - CVE-2021-20865 
* Obtain a list of information without the access permission - CVE-2021-20866 
* Move the field group without the usage permission - CVE-2021-20867
 
 | 
 
[Update the plugin] 
Update the plugin according to the information provided by the developer. 
The developer has released the versions listed below that address the vulnerabilities. 
 
* Advanced Custom Fields 5.11 
* Advanced Custom Fields Pro 5.11
 
 | 
 
	Delicious Brains
	
 
 | 
 
	- No Mapping(CWE-Other) [IPA Evaluation]
 
 
 
 | 
 
	- CVE-2021-20865 
 
	- CVE-2021-20866 
 
	- CVE-2021-20867 
 
 
 
 | 
 
	- JVN : JVN#09136401 
 
	- National Vulnerability Database (NVD) : CVE-2021-20865 
 
	- National Vulnerability Database (NVD) : CVE-2021-20866 
 
	- National Vulnerability Database (NVD) : CVE-2021-20867 
 
 
 
 | 
 
	- [2021/12/02]
 
  Web page was published 
	- [2022/01/05]
 
  Overview was modified 
  Impact was modified 
  Solution was modified 
	- [2022/02/18]
 
  Vendor Information : Content was added 
  
 
 |