Incorrect Permission Assignment Vulnerability in GroupSession by Cloud
CVE-2021-20874

7.5HIGH

What is CVE-2021-20874?

A vulnerability exists in the GroupSession software that allows an unauthenticated remote attacker to exploit incorrect permission settings. This flaw can lead to unauthorized access to critical server files and potentially expose sensitive information without the need for any authentication. It affects multiple versions of GroupSession, specifically those released prior to version 5.1.1, heightening the risk for users relying on vulnerable editions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

GroupSession Free edition, GroupSession byCloud, GroupSession ZION GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.