CVE-2021-36758

1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Malicious users authorized to create Secrets Automation access tokens can create tokens that have access beyond what the user is authorized to access, but limited to the existing authorizations of the Secret Automation the token is created in.
References
Link Resource
https://support.1password.com/kb/202106/ Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:1password:connect:*:*:*:*:*:*:*:*

History

05 Aug 2021, 14:39

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.5
v3 : 5.4
CWE CWE-863
CWE-20
CPE cpe:2.3:a:1password:connect:*:*:*:*:*:*:*:*
References (MISC) https://support.1password.com/kb/202106/ - (MISC) https://support.1password.com/kb/202106/ - Patch, Vendor Advisory

16 Jul 2021, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-16 00:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-36758

Mitre link : CVE-2021-36758

CVE.ORG link : CVE-2021-36758


JSON object : View

Products Affected

1password

  • connect
CWE
CWE-20

Improper Input Validation

CWE-863

Incorrect Authorization