cvelist/2021/20xxx/CVE-2021-20791.json
2021-09-17 02:00:59 +00:00

67 lines
2.1 KiB
JSON

{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2021-20791",
"ASSIGNER": "vultures@jpcert.or.jp",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "J\u2019s Communication Co., Ltd.",
"product": {
"product_data": [
{
"product_name": "RevoWorks Browser",
"version": {
"version_data": [
{
"version_value": "2.1.230 and earlier"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Improper Access Control"
}
]
}
]
},
"references": {
"reference_data": [
{
"url": "https://jscom.jp/news-20210910_2/",
"refsource": "MISC",
"name": "https://jscom.jp/news-20210910_2/"
},
{
"url": "https://jvn.jp/en/jp/JVN81658818/index.html",
"refsource": "MISC",
"name": "https://jvn.jp/en/jp/JVN81658818/index.html"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "Improper access control vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to bypass access restriction and to exchange unauthorized files between the local environment and the isolated environment or settings of the web browser via unspecified vectors."
}
]
}
}