Skip to content

CVE-2021-42562: Improper Access Control in MITRE Caldera

Notifications You must be signed in to change notification settings

mbadanoiu/CVE-2021-42562

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 

Repository files navigation

CVE-2021-42562: Improper Access Control in MITRE Caldera

Caldera (versions <=2.8.1) does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other components which should only be accessible by admin users.

Vendor Disclosure:

The vendor's disclosure for this vulnerability can be found here.

Requirements:

This vulnerability requires:

  • Valid non-admin user credentials

Proof Of Concept:

More details and the exploitation process can be found in this PDF.

Additional Resources:

This vulnerability allows a non-admin user to exploit the vulnerability CVE-2021-42559: Command Injection via Configurations in MITRE Caldera in order to achieve remote code execution.