CVE-2021-45379

HIGH

Glewlwyd < 2.6.1 - Authentication Bypass

Title source: rule
STIX 2.1

Description

Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in as another user without its password.

References (2)

Core 2
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/babelouest/glewlwyd/releases/tag/v2.6.1

Scores

CVSS v3 8.8
EPSS 0.0030
EPSS Percentile 53.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
glewlwyd_project/glewlwyd 2.0.0 - 2.6.1
Published Dec 30, 2021
Tracked Since Feb 18, 2026