« Volver al listado

CVE-2021-20784

Estado: ModificadaMedia (6.1)—

HTTP header injection vulnerability in Everything version 1.0, 1.1, and 1.2 except the Lite version may allow a remote attacker to inject an arbitrary script or alter the website that uses the product.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-20784",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "vultures@jpcert.or.jp",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "voidtools",
          "product": "Everything",
          "versions": [
            {
              "status": "affected",
              "version": "all versions of 1.0 (Everything 1.0 series) except the Lite version"
            }
          ]
        },
        {
          "vendor": "voidtools",
          "product": "Everything",
          "versions": [
            {
              "status": "affected",
              "version": "all versions of 1.1 (Everything 1.1 series) except the Lite version"
            }
          ]
        },
        {
          "vendor": "voidtools",
          "product": "Everything",
          "versions": [
            {
              "status": "affected",
              "version": "all versions of 1.2 (Everything 1.2 series) except the Lite version"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-07-14T02:15:07.577",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN68971465/",
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.voidtools.com/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.voidtools.com/downloads/",
      "tags": [
        "Product",
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN68971465/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.voidtools.com/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.voidtools.com/downloads/",
      "tags": [
        "Product",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vultures@jpcert.or.jp",
      "description": [
        {
          "lang": "en",
          "value": "CWE-644"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HTTP header injection vulnerability in Everything version 1.0, 1.1, and 1.2 except the Lite version may allow a remote attacker to inject an arbitrary script or alter the website that uses the product."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de inyección de encabezado HTTP en Everything todas las versiones, excepto la versión Lite, puede permitir a un atacante remoto inyectar un script arbitrario o alterar el sitio web que usa el producto por medio de vectores no especificados"
    }
  ],
  "lastModified": "2026-06-17T03:34:26.860",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:voidtools:everything:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "54ED65DC-1DED-4D08-85C0-CB2F6011AA5C",
              "versionEndExcluding": "1.1"
            },
            {
              "criteria": "cpe:2.3:a:voidtools:everything:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6DC1904-72E3-4FB3-A304-678A31B12AF6",
              "versionEndExcluding": "1.2",
              "versionStartIncluding": "1.1"
            },
            {
              "criteria": "cpe:2.3:a:voidtools:everything:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B7D356F0-BA1E-4003-9CAD-4BC94F678B2B",
              "versionEndExcluding": "1.3",
              "versionStartIncluding": "1.2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}