« Volver al listado

CVE-2021-20874

Estado: ModificadaAlta (7.5)—

Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to access arbitrary files on the server and obtain sensitive information via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-20874",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "Japan Total System Co.,Ltd.",
          "product": "GroupSession Free edition, GroupSession byCloud, GroupSession ZION",
          "versions": [
            {
              "status": "affected",
              "version": "GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-12-24T07:15:06.700",
  "references": [
    {
      "url": "https://groupsession.jp/info/info-news/security20211220",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN79798166/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://groupsession.jp/info/info-news/security20211220",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN79798166/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to access arbitrary files on the server and obtain sensitive information via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Una asignación incorrecta de permisos para la vulnerabilidad de recursos críticos en GroupSession Free edition versiones 5.1.1 y anteriores, GroupSession byCloud versiones 5.1.1 y anteriores, y GroupSession ZION versiones 5.1.1 y anteriores, permite a un atacante remoto no autenticado acceder a archivos arbitrarios en el servidor y obtener información confidencial por medio de vectores no especificados"
    }
  ],
  "lastModified": "2026-06-17T03:34:35.457",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:groupsession:groupsession:*:*:*:*:cloud:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0AB1821-FA7C-41F4-9F3D-D61B778385F9",
              "versionEndIncluding": "5.1.1"
            },
            {
              "criteria": "cpe:2.3:a:groupsession:groupsession:*:*:*:*:free:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B51AF142-FBF4-4602-BFD4-DD71D0EB0C3E",
              "versionEndIncluding": "5.1.1"
            },
            {
              "criteria": "cpe:2.3:a:groupsession:groupsession:*:*:*:*:zion:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4027BB4D-AE22-43B5-A206-94E71D7B6687",
              "versionEndIncluding": "5.1.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}