Security Advisory Bulletin 021
Overview
First Published: November 24, 2021
Version: 1.1
Revision: 1.1
Summary
A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.
This vulnerability is fixed in UniFi Protect application Version 1.20.0 and later.
Affected Products:
All UniFi OS Consoles hosting the UniFi Protect application
Mitigation:
Update the UniFi Protect application to Version 1.20.0 or later.
Impact:
CVSS v3.0 Severity and Metrics:
Base Score: 7.5 High
Vector:
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE: CVE-2021-22957 Nikita Stupin (nikitastupin)
Reference Links: