Description
Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
Disable remote access to crafter-search.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2427 | Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes. |
Github GHSA |
GHSA-2wr2-8qjq-gh55 | Exposure of Resource to Wrong Sphere in org.craftercms:crafter-search |
References
History
No history.
Status: PUBLISHED
Assigner: crafter
Published:
Updated: 2024-09-16T19:15:49.969Z
Reserved: 2021-01-08T00:00:00.000Z
Link: CVE-2021-23264
No data.
Status : Modified
Published: 2021-12-02T16:15:07.787
Modified: 2024-11-21T05:51:27.873
Link: CVE-2021-23264
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA