Missing Encryption of Sensitive Data in LedgerSMB - CVE-2021-3882

 

Missing Encryption of Sensitive Data in LedgerSMB - CVE-2021-3882

Published: November 4, 2024


Vulnerability identifier: #VU99654
CSH Severity: Medium
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3882
CWE-ID: CWE-311
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. A remote attacker can trick a user into using an unencrypted connection (HTTP) to obtain the authentication data by capturing network traffic.


Affected software

LedgerSMB
Ubuntu
ledgersmb (Ubuntu package)
Planning Analytics Local
IBM Planning Analytics Workspace

How to mitigate CVE-2021-3882

Install updates from vendor's website.

LedgerSMB - update to 1.8.22
ledgersmb (Ubuntu package) - addressed in versions 1.3.46-1ubuntu0.1~esm1, 1.4.42+ds-1ubuntu0.1~esm1, 1.6.9+ds-1ubuntu0.1+esm1, 1.6.33+ds-1ubuntu0.1, 1.6.33+ds-2.1ubuntu0.1, 1.6.33+ds-2.2ubuntu0.25.04.1
Planning Analytics Local - update to 2.0.9.11
IBM Planning Analytics Workspace - update to 2.0.72

External References

Related Security Bulletins