PT-2021-18249 · October · October/System

·

CVE-2021-29487

·

Published

2021-08-26

·

Updated

2022-08-02

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: october/system package versions prior to v1.1.5 october/system package versions prior to Build 472
Description: The issue allows an attacker to bypass authentication and take over a user account on an October CMS server. This can be exploited by unauthenticated users via a specially crafted request, affecting only frontend users. To exploit this vulnerability, the attacker must obtain a Laravel secret key for cookie encryption and signing.
Recommendations: For versions prior to v1.1.5, update to v1.1.5 or later to resolve the issue. For versions prior to Build 472, update to Build 472 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the October CMS server until the issue is resolved. Avoid using the vulnerable october/system package until the issue is resolved.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29487
GHSA-H76R-VGF3-J6W5

Affected Products

October/System