[Japanese]
|
JVNDB-2021-000109
|
Multiple missing authorization vulnerabilities in WordPress Plugin "Advanced Custom Fields"
|
WordPress Plugin "Advanced Custom Fields" provided by Delicious Brains contains multiple missing authorization vulnerabilities listed below.
* Missing authorization related to database browsing (CWE-862) - CVE-2021-20865
* Missing authorization related to user list obtaining (CWE-862) - CVE-2021-20866
* Missing authorization related to field group movement (CWE-862) - CVE-2021-20867
Keitaro Yamazaki of Ierae Security, Inc reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 4.3 (Medium) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: None
CVSS V2 Severity: Base Metrics 4.0 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: Single Instance
- Confidentiality Impact: Partial
- Integrity Impact: None
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2021-20865
|
CVSS V3 Severity: Base Metrics 4.3 (Medium) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: None
CVSS V2 Severity:Base Metrics 4.0 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: Single
- Confidentiality Impact: Partial
- Integrity Impact: None
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2021-20866
|
CVSS V3 Severity: Base Metrics 4.3 (Medium) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
CVSS V2 Severity:Base Metrics 4.0 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: Single
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2021-20867
|
|
Delicious Brains
- Advanced Custom Fields 5.11 prior to 5.11
- Advanced Custom Fields Pro 5.11 prior to 5.11
|
|
A user with a lower level of authority than Editor role (such as Subscriber, Contributor, Author roles) may:
* View the information on the database without the access permission - CVE-2021-20865
* Obtain a list of information without the access permission - CVE-2021-20866
* Move the field group without the usage permission - CVE-2021-20867
|
[Update the plugin]
Update the plugin according to the information provided by the developer.
The developer has released the versions listed below that address the vulnerabilities.
* Advanced Custom Fields 5.11
* Advanced Custom Fields Pro 5.11
|
Delicious Brains
|
- No Mapping(CWE-Other) [IPA Evaluation]
|
- CVE-2021-20865
- CVE-2021-20866
- CVE-2021-20867
|
- JVN : JVN#09136401
- National Vulnerability Database (NVD) : CVE-2021-20865
- National Vulnerability Database (NVD) : CVE-2021-20866
- National Vulnerability Database (NVD) : CVE-2021-20867
|
- [2021/12/02]
Web page was published
- [2022/01/05]
Overview was modified
Impact was modified
Solution was modified
- [2022/02/18]
Vendor Information : Content was added
|