Skip to content

Authorization Bypass in Space Invite

Moderate
luke- published GHSA-f5hc-5wfr-7v74 Dec 20, 2021

Package

Core (HumHub)

Affected versions

< 1.10.3

Patched versions

1.10.3

Description

Impact

It could be possible for registered users to become unauthorized members of private Spaces.

Patches

It is recommended that the HumHub is upgraded to 1.10.3 or 1.9.3.

References

For more information

If you have any questions or comments about this advisory:

  • Create a post in our Community
  • Customers: Open a support ticket

Severity

Moderate

CVE ID

CVE-2021-43847

Weaknesses

No CWEs

Credits