OSV 1.4.0 · unreviewed · 修改于 2021-12-22 08:01
发布时间
2021-12-16 08:00
GitHub 审查时间
—
NVD 发布时间
2021-12-16 04:15
源文件
advisories/unreviewed/2021/12/GHSA-fr6w-vm34-xj98/GHSA-fr6w-vm34-xj98.json
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows an authenticated, remote attacker with read-only privileges to create an account with administrative privileges. Older versions of FatPipe software may also be vulnerable. This does not appear to be a CSRF vulnerability. The FatPipe advisory identifier for this vulnerability is FPSA005.
该公告没有提供结构化的受影响软件包信息。