« Volver al listado

CVE-2021-28938

Estado: ModificadaMedia (4.3)—

Siren Federate before 6.8.14-10.3.9, 6.9.x through 7.6.x before 7.6.2-20.2, 7.7.x through 7.9.x before 7.9.3-21.6, 7.10.x before 7.10.2-22.2, and 7.11.x before 7.11.2-23.0 can leak user information across thread contexts. This occurs in opportunistic circumstances when there is concurrent query execution by a low-privilege user and a high-privilege user. The former query might run with the latter query's privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-28938",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-04-13T06:15:12.420",
  "references": [
    {
      "url": "https://docs.siren.io/siren-federate-user-guide/22/siren-federate/release-notes.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://docs.siren.io/siren-federate-user-guide/22/siren-federate/release-notes.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Siren Federate before 6.8.14-10.3.9, 6.9.x through 7.6.x before 7.6.2-20.2, 7.7.x through 7.9.x before 7.9.3-21.6, 7.10.x before 7.10.2-22.2, and 7.11.x before 7.11.2-23.0 can leak user information across thread contexts. This occurs in opportunistic circumstances when there is concurrent query execution by a low-privilege user and a high-privilege user. The former query might run with the latter query's privileges."
    },
    {
      "lang": "es",
      "value": "Sirena Federate versiones anteriores a 6.8.14-10.3.9, versiones 6.9.x hasta 7.6.x versiones anteriores a 7.6.2-20.2, versiones 7.7.x hasta 7.9.x versiones anteriores a 7.9.3-21.6,  versiones 7.10.x anteriores a 7.10.2-22.2, y versiones 7.11.x anteriores a 7.11.2-23.0, puede filtrar información de usuario en contextos de subprocesos. Esto ocurre en circunstancias oportunistas cuando se presenta una ejecución simultánea de consultas por parte de un usuario poco privilegiado y un usuario muy privilegiado. La primera consulta puede ejecutarse con los privilegios de la última consulta"
    }
  ],
  "lastModified": "2026-06-17T03:47:03.493",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siren:federate:*:*:*:*:*:elasticsearch:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F3307B1C-19E2-40CA-86C2-C6E08DDCF860",
              "versionEndExcluding": "6.8.14-10.3.9"
            },
            {
              "criteria": "cpe:2.3:a:siren:federate:*:*:*:*:*:elasticsearch:*:*",
              "vulnerable": true,
              "matchCriteriaId": "897F620C-A917-44C1-87DE-F6313F963516",
              "versionEndExcluding": "7.6.2-20.2",
              "versionStartIncluding": "7.3.2-19.0"
            },
            {
              "criteria": "cpe:2.3:a:siren:federate:*:*:*:*:*:elasticsearch:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0AB5482B-5A53-4071-A6C8-1DF091BC0DA9",
              "versionEndExcluding": "7.9.3-21.6",
              "versionStartIncluding": "7.7.1-20.0"
            },
            {
              "criteria": "cpe:2.3:a:siren:federate:*:*:*:*:*:elasticsearch:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B18A0F0-510E-46F5-BACE-EF8528ABF395",
              "versionEndExcluding": "7.10.2-22.2",
              "versionStartIncluding": "7.10.1-22.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}