CVE-2021-41152
Last modified
CVE-2021-41152 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system. In affected versions by manipulating the HTTP request an attacker can modify the path of a requested file download in the folder component to point to anywhere on the target system. EPSS estimates a 1.20% chance of exploitation in the next 30 days.
Description
OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system. In affected versions by manipulating the HTTP request an attacker can modify the path of a requested file download in the folder component to point to anywhere on the target system. The attack could be used to read any file accessible in the web root folder or outside, depending on the configuration of the system and the properly configured permission of the application server user. The attack requires an OpenOlat user account or the enabled guest user feature together with the usage of the folder component in a course. The attack does not allow writing of arbitrary files, it allows only reading of files and also only ready of files that the attacker knows the exact path which is very unlikely at least for OpenOlat data files. The problem is fixed in version 15.5.8 and 16.0.1 It is advised to upgrade to version 16.0.x. There are no known workarounds to fix this problem, an upgrade is necessary.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Frentix | Openolat | < 15.5.8 |
References
- https://github.com/OpenOLAT/OpenOLAT/commit/418bb509ffcb0e25ab4390563c6c47f0458583ebPatch, Third Party Advisory
- https://github.com/OpenOLAT/OpenOLAT/security/advisories/GHSA-m8j5-837g-2p3fThird Party Advisory
- https://jira.openolat.org/browse/OO-5696Permissions Required, Vendor Advisory
- https://github.com/OpenOLAT/OpenOLAT/commit/418bb509ffcb0e25ab4390563c6c47f0458583ebPatch, Third Party Advisory
- https://github.com/OpenOLAT/OpenOLAT/security/advisories/GHSA-m8j5-837g-2p3fThird Party Advisory
- https://jira.openolat.org/browse/OO-5696Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-41152?
How severe is CVE-2021-41152?
How do I fix CVE-2021-41152?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-41147Tuleap Open ALM is a libre and open source tool for end to e…7.2
- CVE-2021-41148Tuleap Open ALM is a libre and open source tool for end to e…8.8
- CVE-2021-41149Tough provides a set of Rust libraries and tools for using a…8.1
- CVE-2021-4115There is a flaw in polkit which can allow an unprivileged us…5.5
- CVE-2021-41150Tough provides a set of Rust libraries and tools for using a…6.5
- CVE-2021-41151Backstage is an open platform for building developer portals…4.9
- CVE-2021-41153The evm crate is a pure Rust implementation of Ethereum Virt…9.8
- CVE-2021-41154Tuleap is a Free & Open Source Suite to improve management o…8.8
- CVE-2021-41155Tuleap is a Free & Open Source Suite to improve management o…8.8
- CVE-2021-41156anuko/timetracker is an, open source time tracking system. I…5.4
- CVE-2021-41157FreeSWITCH is a Software Defined Telecom Stack enabling the …5.3
- CVE-2021-41158FreeSWITCH is a Software Defined Telecom Stack enabling the …7.5
Are you affected by CVE-2021-41152?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
