Candidate: CVE-2021-45379 PublicDate: 2021-12-30 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45379 https://github.com/babelouest/glewlwyd/commit/125281f1c0d4b6a8b49f7e55a757205a2ef01fbe (v2.6.1) https://github.com/babelouest/glewlwyd/releases/tag/v2.6.1 https://github.com/babelouest/glewlwyd/commit/125281f1c0d4b6a8b49f7e55a757205a2ef01fbe Description: Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in as another user without its password. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_glewlwyd: upstream_glewlwyd: released (2.6.1-1) trusty_glewlwyd: ignored (out of standard support) xenial_glewlwyd: ignored (out of standard support) bionic_glewlwyd: needs-triage focal_glewlwyd: needs-triage hirsute_glewlwyd: ignored (reached end-of-life) impish_glewlwyd: needs-triage jammy_glewlwyd: needs-triage devel_glewlwyd: needs-triage