{ "id": "CVE-2021-41329", "sourceIdentifier": "cve@mitre.org", "published": "2021-09-27T06:15:08.057", "lastModified": "2024-11-21T06:26:03.963", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Datalust Seq before 2021.2.6259 allows users (with view filters applied to their accounts) to see query results not constrained by their view filter. This information exposure, caused by an internal cache key collision, occurs when the user's view filter includes an array or IN clause, and when another user has recently executed an identical query differing only by the array elements." }, { "lang": "es", "value": "Datalust Seq versiones anteriores a 2021.2.6259, permite a usuarios (con filtros de visualizaci\u00f3n aplicados a sus cuentas) visualizar los resultados de la consulta no restringidos por su filtro de visualizaci\u00f3n. Esta exposici\u00f3n de la informaci\u00f3n, causada por una colisi\u00f3n de claves de la cach\u00e9 interna, se produce cuando el filtro de visualizaci\u00f3n del usuario incluye una cl\u00e1usula de matriz o IN, y cuando otro usuario ha ejecutado recientemente una consulta id\u00e9ntica que difiere s\u00f3lo por los elementos de la matriz" } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "baseScore": 6.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE" }, "exploitabilityScore": 2.8, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N", "baseScore": 4.0, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-682" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:datalust:seq:*:*:*:*:*:*:*:*", "versionEndExcluding": "2021.2.6259", "matchCriteriaId": "646C75F9-1BA1-4BF1-8CA9-DD3A505BC6FA" } ] } ] } ], "references": [ { "url": "https://blog.datalust.co", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "https://github.com/datalust/seq-tickets/issues/1322", "source": "cve@mitre.org", "tags": [ "Exploit", "Third Party Advisory" ] }, { "url": "https://blog.datalust.co", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "https://github.com/datalust/seq-tickets/issues/1322", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit", "Third Party Advisory" ] } ] }