« Volver al listado

CVE-2011-4311

Estado: ModificadaMedia (5)—

ResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-4311",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-11-19T03:58:55.680",
  "references": [
    {
      "url": "http://openwall.com/lists/oss-security/2011/11/13/2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2011/11/14/3",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.resourcespace.org/download.php",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2011/11/13/2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://openwall.com/lists/oss-security/2011/11/14/3",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.resourcespace.org/download.php",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "ResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "ResourceSpace antes de v4.02.2833 no valida correctamente las claves de acceso, lo que permite a atacantes remotos evitar las restricciones de los recursos a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-16T23:34:44.920",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C38AE3CB-68EB-4912-A511-4A63E8E5A4A0",
              "versionEndIncluding": "4.2.2816"
            },
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:2.2.1240:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52AD45F5-445F-4FCB-956A-4CF9D5F40F5C"
            },
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:2.3.1374:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "957E93D7-8A99-4833-ACCF-B962F5230521"
            },
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:3.0.1490:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F31881B6-CDE6-4FD1-B478-9E68D12EF7ED"
            },
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:3.1.1557:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D941F016-7159-40F1-9766-DD35BDAFF845"
            },
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:3.2.1651:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "94250016-6E5E-4E19-BD3C-582A0C4635DA"
            },
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:3.3.1723:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "758FD1C3-386A-4023-9071-4D586B5CE101"
            },
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:3.4.1794:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17D3EE93-8486-4160-9D48-AE5B59BA4249"
            },
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:3.5.1857:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EAB3221-8A15-4C92-A43E-9122F067E9B7"
            },
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:3.6.2022:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2450ACA2-D216-4AF1-9578-D602D4901AB8"
            },
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:3.7.2088:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C86694B-12A0-4AA8-899D-F0990EA8C9B9"
            },
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:3.8.2144:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "638866F8-C485-4927-8034-1944779392AC"
            },
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:3.9.2269:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60685610-36EC-4388-904C-506A003C819A"
            },
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:4.0.2429:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21AD3E99-4807-4568-B68F-A56B3B18547C"
            },
            {
              "criteria": "cpe:2.3:a:montala:resourcespace:4.1.2567:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80269ABE-3407-46AF-A76B-C15893D08073"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}