Skip to content

Any logged in user could edit any other logged in user.

High
evert published GHSA-8hw9-22v6-9jr9 Apr 16, 2021

Package

npm a12nserver (npm)

Affected versions

>= 0.18 < 0.18.2

Patched versions

0.18.2

Description

Impact

Everyone who is running a12n-server.

A new HAL-Form was added to allow editing users. This feature should only have been accessible to admins. Unfortunately, privileges were incorrectly checked allowing any logged in user to make this change.

Patches

Patched in v0.18.2

References

Are there any links users can visit to find out more?

Severity

High

CVE ID

CVE-2021-29452

Weaknesses

No CWEs