CVE-2021-36076
published 2021-09-01CVE-2021-36076: Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.71%
84.2th percentile
Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | bridge | <= 11.1 | — |
| adobe | bridge | unspecified – 11.1 | — |
| nodebb | nodebb | >= 0 < 1.17.2 | 1.17.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
NodeBB account takeover via SSO plugins
ghsa·2022-09-16
CVE-2022-36076 [HIGH] CWE-352 NodeBB account takeover via SSO plugins
NodeBB account takeover via SSO plugins
_This is a historical security advisory, pertaining to a vulnerability that was reported, patched, and published in 2021. It is listed here for completeness and for CVE tracking purposes._
### Impact
Due to an unnecessarily strict conditional in the code handling the first step of the SSO process, the pre-existing logic that added (and later checked) a nonce was inadvertently rendered opt-in instead of opt-out.
This re-exposed a vulnerability in that a specially crafted MITM attack could theoretically take over another user account during the single sign-on process.
### Patches
The issue has been fully patched as of v1.17.2.
The patch commit can be found at https://github.com/NodeBB/NodeBB/commit/a2400f6baff44cb2996487bcd0cc6e2acc74b3d4
### Wor
GHSA
GHSA-g329-m66c-j346: Adobe Bridge version 11
ghsa_unreviewed·2022-05-24
CVE-2021-36076 [HIGH] CWE-119 GHSA-g329-m66c-j346: Adobe Bridge version 11
Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-09-01
Published