Show plain JSON{"containers": {"cna": {"affected": [{"product": "humhub", "vendor": "humhub", "versions": [{"status": "affected", "version": ">= 1.10.0, < 1.10.3"}, {"status": "affected", "version": "< 1.9.3"}]}], "descriptions": [{"lang": "en", "value": "HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue."}], "metrics": [{"cvssV3_1": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.1"}}], "problemTypes": [{"descriptions": [{"cweId": "CWE-285", "description": "CWE-285: Improper Authorization", "lang": "en", "type": "CWE"}]}], "providerMetadata": {"dateUpdated": "2021-12-20T21:35:12", "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "shortName": "GitHub_M"}, "references": [{"tags": ["x_refsource_CONFIRM"], "url": "https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74"}, {"tags": ["x_refsource_MISC"], "url": "https://github.com/humhub/humhub/pull/5473"}, {"tags": ["x_refsource_MISC"], "url": "https://github.com/humhub/humhub/releases/tag/v1.10.3"}, {"tags": ["x_refsource_MISC"], "url": "https://github.com/humhub/humhub/releases/tag/v1.9.3"}, {"tags": ["x_refsource_MISC"], "url": "https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/"}], "source": {"advisory": "GHSA-f5hc-5wfr-7v74", "discovery": "UNKNOWN"}, "title": "Authorization Bypass in Space Invite in HumHub", "x_legacyV4Record": {"CVE_data_meta": {"ASSIGNER": "security-advisories@github.com", "ID": "CVE-2021-43847", "STATE": "PUBLIC", "TITLE": "Authorization Bypass in Space Invite in HumHub"}, "affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"product_name": "humhub", "version": {"version_data": [{"version_value": ">= 1.10.0, < 1.10.3"}, {"version_value": "< 1.9.3"}]}}]}, "vendor_name": "humhub"}]}}, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": {"description_data": [{"lang": "eng", "value": "HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 contain a patch for this issue."}]}, "impact": {"cvss": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.1"}}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "CWE-285: Improper Authorization"}]}]}, "references": {"reference_data": [{"name": "https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74", "refsource": "CONFIRM", "url": "https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74"}, {"name": "https://github.com/humhub/humhub/pull/5473", "refsource": "MISC", "url": "https://github.com/humhub/humhub/pull/5473"}, {"name": "https://github.com/humhub/humhub/releases/tag/v1.10.3", "refsource": "MISC", "url": "https://github.com/humhub/humhub/releases/tag/v1.10.3"}, {"name": "https://github.com/humhub/humhub/releases/tag/v1.9.3", "refsource": "MISC", "url": "https://github.com/humhub/humhub/releases/tag/v1.9.3"}, {"name": "https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/", "refsource": "MISC", "url": "https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/"}]}, "source": {"advisory": "GHSA-f5hc-5wfr-7v74", "discovery": "UNKNOWN"}}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-04T04:10:17.072Z"}, "title": "CVE Program Container", "references": [{"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "https://github.com/humhub/humhub/security/advisories/GHSA-f5hc-5wfr-7v74"}, {"tags": ["x_refsource_MISC", "x_transferred"], "url": "https://github.com/humhub/humhub/pull/5473"}, {"tags": ["x_refsource_MISC", "x_transferred"], "url": "https://github.com/humhub/humhub/releases/tag/v1.10.3"}, {"tags": ["x_refsource_MISC", "x_transferred"], "url": "https://github.com/humhub/humhub/releases/tag/v1.9.3"}, {"tags": ["x_refsource_MISC", "x_transferred"], "url": "https://huntr.dev/bounties/943dad83-f0ed-4c74-ba81-7dfce7ca0ef2/"}]}]}, "cveMetadata": {"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "assignerShortName": "GitHub_M", "cveId": "CVE-2021-43847", "datePublished": "2021-12-20T21:35:12", "dateReserved": "2021-11-16T00:00:00", "dateUpdated": "2024-08-04T04:10:17.072Z", "state": "PUBLISHED"}, "dataType": "CVE_RECORD", "dataVersion": "5.1"}