CVE-2021-20789
Estado: ModificadaMedia (6.1)—
Open redirect vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack via a specially crafted URL.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.87%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-601
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-20789",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "Japan Total System Co.,Ltd.",
"product": "GroupSession",
"versions": [
{
"status": "affected",
"version": "GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0"
}
]
}
]
}
],
"published": "2021-07-30T14:15:14.893",
"references": [
{
"url": "https://groupsession.jp/info/info-news/security202107",
"tags": [
"Vendor Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://jvn.jp/en/jp/JVN86026700/index.html",
"tags": [
"Third Party Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://groupsession.jp/info/info-news/security202107",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://jvn.jp/en/jp/JVN86026700/index.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-601"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Open redirect vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack via a specially crafted URL."
},
{
"lang": "es",
"value": "Una vulnerabilidad de redirección abierta en GroupSession (GroupSession Free edition desde versión 2.2.0 hasta versión anterior a ver5.1.0, GroupSession byCloud desde versión 3.0.3 hasta versión anterior a ver5.1.0, y GroupSession ZION desde versión 3.0.3 hasta versión anterior a ver5.1.0) permite a un atacante remoto redirigir a un usuario a un sitio web arbitrario y conducir un ataque de phishing por medio de una URL especialmente diseñada"
}
],
"lastModified": "2026-06-17T03:34:27.370",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:groupsession:groupsession:*:*:*:*:free:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BCD711A0-12D3-4FC1-B1F3-084DD5D9721B",
"versionEndExcluding": "5.1.0",
"versionStartIncluding": "2.20"
},
{
"criteria": "cpe:2.3:a:groupsession:groupsession_bycloud:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20139ED3-424E-49EB-9D6D-9EAA356C0D96",
"versionEndExcluding": "5.1.0",
"versionStartIncluding": "3.0.3"
},
{
"criteria": "cpe:2.3:a:groupsession:groupsession_zion:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F38C4EF-470B-4C54-B57F-7C99AB59BF73",
"versionEndExcluding": "5.1.0",
"versionStartIncluding": "3.0.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vultures@jpcert.or.jp"
}