René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

120 lines
3.5 KiB
JSON

{
"id": "CVE-2020-13963",
"sourceIdentifier": "cve@mitre.org",
"published": "2021-03-21T21:15:12.530",
"lastModified": "2022-11-05T02:04:33.607",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation code, and there is no key for publicsp (which is a guest account)."
},
{
"lang": "es",
"value": "SOPlanning versiones anteriores a 1.47, presenta un Control de Acceso Incorrecto porque determinada informaci\u00f3n de clave secreta y el algoritmo de autenticaci\u00f3n relacionado es p\u00fablico. La clave de administrador est\u00e1 embebida en el c\u00f3digo de instalaci\u00f3n y no existe clave para publicsp (que es una cuenta de invitado)"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*:*",
"versionStartIncluding": "1.45",
"versionEndExcluding": "1.47",
"matchCriteriaId": "0C314621-724F-435A-8B74-3C7CD3A4CAB6"
}
]
}
]
}
],
"references": [
{
"url": "https://cwe.mitre.org/data/definitions/321.html",
"source": "cve@mitre.org",
"tags": [
"Technical Description"
]
},
{
"url": "https://forum.soplanning.org/viewforum.php?f=8",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://labs.integrity.pt/advisories/cve-2020-13963/",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory"
]
}
]
}