Update für UniFi Protect steht zur Verfügung

    • Offizieller Beitrag

    Security Advisory Bulletin 021


    Overview

    First Published: November 24, 2021

    Version: 1.1

    Revision: 1.1


    Summary

    A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.


    This vulnerability is fixed in UniFi Protect application Version 1.20.0 and later.


    Affected Products:

    All UniFi OS Consoles hosting the UniFi Protect application

    Mitigation:

    Update the UniFi Protect application to Version 1.20.0 or later.


    Impact:

    CVSS v3.0 Severity and Metrics:

    Base Score: 7.5 High

    Vector:

    CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

    CVE: CVE-2021-22957 Nikita Stupin (nikitastupin)


    Reference Links:

    https://community.ui.com/relea…b4-456b-a7ca-73aa830cb011