CVE-2021-36383

CVE-2021-36383

Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacker changes the permission field from none to admin. The attacker gains access to data sets such as VMs, Backups, Audit, Users, and Groups.

Source: CVE-2021-36383

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다